Vulnerability  ·  2026-09-20

Process Compose MCP SSE listener accepts unauthenticated browser-origin requests (DNS rebinding)

VulnerabilityMedium impactGlobalCVE-2026-77339
NVD published this CVSS 5.1 Medium vulnerability on Sept 18, 2026 describing a DNS-rebinding-exploitable authentication gap in a local process orchestrator's MCP interface.
This is part of a recurring class of MCP SSE/HTTP transport implementations that omit Host/Origin validation, letting any webpage a developer visits pivot into local developer tooling and orchestrated processes — a low-cost but recurring class of exposure across the MCP ecosystem.
The MCP SSE listener accepts browser-origin requests to /sse and its message endpoint without validating the Host header, validating the Origin header, or requiring caller authentication, enabling a malicious website to use DNS rebinding to control a developer's local MCP SSE session.
Process Compose prior to 1.120.0
Upgrade to Process Compose 1.120.0 or later per the vendor's GitHub commit fix.
GitHub commit fixNVD
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →