CVE-2026-81095
Received Received - Intake

pg-aiguide MCP HTTP Transport Host Allow-List Bypass

Vulnerability report for CVE-2026-81095, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-29

Assigner: VulnCheck

Description

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named. A page in a browser could therefore point a name it controlled at the address the server was bound to and drive the locally reachable MCP server through the visitor's browser. The protection was already available in the packaged transport and simply not turned on, so updating the dependency alone would not have closed it. Version 0.5.1 passes the option explicitly.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-29
Generated
2026-09-16
AI Q&A
2026-08-27
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
pg-aiguide mcp_http_transport 0.5.1
timescale pg-aiguide to 0.5.1 (exc)
timescale pg-aiguide 0.5.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a DNS rebinding attack due to a missing host header allow-list in the MCP HTTP transport of pg-aiguide. The SDK provided DNS-rebinding protection but it was not enabled in the implementation. An attacker could exploit this by directing a controlled hostname to the server's address, allowing interaction with the locally reachable MCP server through a victim's browser.

Detection Guidance

Check if pg-aiguide is running a vulnerable version (0.5.0 or earlier) by inspecting the package version in your environment. Verify if DNS rebinding protection is disabled by examining the HTTP server configuration in src/httpServer.ts for the missing dnsRebindingProtection setting.

Impact Analysis

An attacker could exploit this to interact with your locally running MCP server via a browser, potentially accessing sensitive data or executing unauthorized actions. The impact includes high confidentiality and integrity risks as the attacker could read or modify data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Compliance may be impacted due to increased risk of data breaches.

Mitigation Strategies

Upgrade pg-aiguide to version 0.5.1 or later, which explicitly enables DNS rebinding protection. Ensure the dnsRebindingProtection option is set in the HTTP server configuration, especially for local development environments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81095. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart