CVE-2026-81099
Received Received - Intake

Tiger-Slack MCP HTTP Transport Host Allow-List Bypass

Vulnerability report for CVE-2026-81099, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: VulnCheck

Description

tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, and a page in a browser could point a name it controlled at the address the server was bound to and drive the locally reachable Slack MCP server through the visitor's browser. The fix passes the option explicitly alongside a dependency update; the update alone would not have closed it. The repository publishes no release that brackets the fix, so the affected boundary is the commit preceding it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-09-17
AI Q&A
2026-08-27
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
timescale tiger_slack to 23faf7ee7e7f73e5ea4f67e627c1aca94bba1f09 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-81099 is a DNS rebinding vulnerability in the tiger-slack component. The MCP HTTP transport did not enable the host allow-list feature provided by the underlying SDK, allowing any host to interact with the locally reachable Slack MCP server through a user's browser. A malicious webpage could exploit this by pointing a controlled DNS name to the server's address.

Detection Guidance

To detect this vulnerability, check if your tiger-slack instance is running a version prior to commit 23faf7ee7e7f73e5ea4f67e627c1aca94bba1f09. Inspect the httpServer.ts file for the absence of DNS rebinding protection settings. Monitor network traffic for unusual requests targeting localhost from browser contexts.

Impact Analysis

An attacker could use this vulnerability to gain unauthorized access to the tiger-slack server running on your local machine. This could allow them to interact with your Slack MCP server, potentially exfiltrating sensitive data or performing actions on your behalf without your knowledge.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. If exploited, it may result in data breaches, triggering compliance violations and potential legal penalties.

Mitigation Strategies

Update tiger-slack to a version that includes the fix by applying commit 23faf7ee7e7f73e5ea4f67e627c1aca94bba1f09 or later. Ensure DNS rebinding protection is explicitly enabled in the MCP HTTP transport configuration. Verify dependency updates, particularly @tigerdata/mcp-boilerplate to version 1.5.0 or higher.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81099. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart