All 4 CVE vulnerabilities found in dbt-mcp, with AI-generated Chinese analysis, references, and POCs.
Vendor: dbt-labs
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55837 | dbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens CWE-200 | 6.8 | Medium | 2026-09-14 |
| CVE-2026-44969 | dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabled CWE-532 | 2.5 | Low | 2026-07-16 |
| CVE-2026-44970 | dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without Redaction CWE-201 | 3.1 | Low | 2026-07-16 |
| CVE-2026-44968 | dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters CWE-88 | 6.3 | Medium | 2026-07-16 |
All 4 known CVE vulnerabilities affecting dbt-mcp with full Chinese analysis, references, and POCs where available.