The Model Context Protocol server does not validate the "Origin" header on incoming connections, making it vulnerable to DNS rebinding attacks where an attacker can cause a victim's browser to make requests to the server as if they originated from an allowed origin.
An unauthenticated attacker can perform DNS rebinding attacks to bypass origin validation and make requests to the server that appear to come from a legitimate origin, potentially allowing unauthorized access to server functionality or data.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Available - v0.25.0 introduces --allowed-hosts and --allowed-origins flags for Origin header validation
Upgrade to v0.25.0 or later and configure the --allowed-hosts and --allowed-origins flags to restrict connections to specific trusted hosts and origins. Do not rely on the default "*" setting in production environments.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-11624 . See article
NVD published the first details for CVE-2026-11624
A CVSS base score of 9.4 has been assigned.
GitHub Advisories released a security advisory .
CVE-2026-11624 - Exploits & Severity - Feedly
CVE-2026-11624 - Model Context Protocol DNS Rebinding Vulnerability CVE ID : CVE-2026-11624 Published : June 13, 2026, 10:16 a.m. | 51 minutes ago Description : The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all inco...
CVE-2026-11624 | Google MCP Toolbox for Databases up to 0.24.x origin validation (Issue 3113 / EUVD-2026-36650)
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
