在启动其 MCP HTTP 传输层时,未启用底层 SDK 提供的“主机白名单”(host allow-list)机制。具体而言, 调用了共享的 辅助函数,但从未设置 DNS 重绑定(DNS-rebinding)防护选项,导致该传输层会接受来自任意 头的请求。因此,攻击者可通过页面中的浏览器,将其控制的域名指向服务器绑定的地址,从而通过访问者的浏览器操控本地可访问的 MCP 服务器。该防护机制在打包的传输层中已经可用,只是未被启用,因此仅更新依赖项本身并不能修复此问题。版本 0.5.1 通过显式传递该选项,从而关闭了
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| timescale | pg-aiguide | ≤ 0.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| timescale | pg-aiguide | 0 ~ 0.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81099 | 6.8 MEDIUM | Timescale tiger-slack DNS Rebinding via Disabled Host Header Allow-List |
| CVE-2026-81100 | 6.8 MEDIUM | Timescale tiger-gh-mcp-server DNS Rebinding via Disabled Host Header Allow-List |
No comments yet