Browse all 8 CVE security advisories affecting dbt-labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
dbt-labs develops dbt, a data transformation tool that enables analysts to convert raw data into analytics through SQL-based models. Historically, their vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation risks, often stemming from improper input validation and access control flaws. While no major public security incidents have been widely reported, the organization maintains four CVE records, highlighting ongoing security considerations. Their open-source nature requires regular security audits, particularly for web interfaces and authentication mechanisms, to mitigate risks associated with third-party dependencies and user-supplied data processing.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55837 | dbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens — dbt-mcp CWE-200 | 6.8 | Medium | 2026-09-14 |
| CVE-2026-44969 | dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabled — dbt-mcp CWE-532 | 2.5 | Low | 2026-07-16 |
| CVE-2026-44970 | dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without Redaction — dbt-mcp CWE-201 | 3.1 | Low | 2026-07-16 |
| CVE-2026-44968 | dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters — dbt-mcp CWE-88 | 6.3 | Medium | 2026-07-16 |
This page lists every published CVE security advisory associated with dbt-labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.