Skip to content
Critical CVE-2026-11624 Vulnerability in Model Context Protocol

Critical CVE-2026-11624 Vulnerability in Model Context Protocol

First seen 14 Jun 2026, 05:19 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 15, 2026 at 05:02 UTC
  • CVE-2026-11624 allows DNS rebinding attacks due to lack of 'Origin' header validation.
  • Upgrade to version 0.25.0 is critical to mitigate this vulnerability.
  • No active exploitation or proof-of-concept has been reported yet.

CVE-2026-11624, published on June 13, 2026, exposes the Model Context Protocol to DNS rebinding attacks due to improper validation of the 'Origin' header. This vulnerability allows unauthenticated attackers to bypass origin validation, potentially leading to unauthorized access to server functionalities and data. The CVSS base score is 9.4, indicating critical severity. Users are advised to upgrade to version 0.25.0 or later, which introduces the '--allowed-hosts' and '--allowed-origins' flags for enhanced security. If these flags are set to '*', a startup warning will be issued, indicating potential vulnerabilities. Currently, there is no public proof-of-concept or evidence of active exploitation. Organizations using affected versions are at risk until they implement the necessary updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 89d ago How this analysis works

Timeline

2026-06-13
CVE-2026-11624 published
CVE-2026-11624 was published, detailing a critical vulnerability in the Model Context Protocol.
Feedly
2026-06-14
CVE-2026-11624 reported by Tenable
Tenable reported on the critical nature of CVE-2026-11624, emphasizing the need for server configuration changes.
www.tenable.com
2026-06-14
INCIBE-CERT alerts on CVE-2026-11624
INCIBE-CERT issued a warning about CVE-2026-11624, highlighting the importance of validating the 'Origin' header.
www.incibe.es

More articles in this cluster (4)

Following this threat?

Track CVE-2026-11624 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed