Vulnerability  ·  2026-09-15

dbt-mcp — unauthenticated local OAuth-context endpoint discloses dbt Platform tokens

VulnerabilityMedium impactGlobalCVE-2026-55837
dbt-mcp is an MCP server bridging LLM agents to dbt data-platform operations; leaking OAuth context lets a local attacker or malicious co-resident process impersonate the user's dbt Platform session through the agent's own tool integration.
The local OAuth helper's GET /dbt_platform_context endpoint is exposed without authentication or Host validation after a user completes the dbt Platform OAuth flow, returning the full platform context (potentially including tokens) to any local process or, if the port is reachable, any network caller.
dbt-mcp < 1.20.0
Upgrade to dbt-mcp 1.20.0.
dbt-mcp commitNVD CVE-2026-55837
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →