Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 1 min read

CVE-2026-63118: CVE-2026-63118: DNS-Rebinding and Cross-Origin Request Execution in Model Context Protocol (MCP) Ruby SDK

CVE-2026-63118: DNS-Rebinding and Cross-Origin Request Execution in Model Context Protocol (MCP) Ruby SDK Vulnerability ID: CVE-2026-63118 CVSS Score: 6.9 Published: 2026-07-30 A critical vulnerability (CVE-2026-631

CVE-2026-63118: DNS-Rebinding and Cross-Origin Request Execution in Model Context Protocol (MCP) Ruby SDK

Vulnerability ID: CVE-2026-63118
CVSS Score: 6.9
Published: 2026-07-30

A critical vulnerability (CVE-2026-63118) in the Model Context Protocol (MCP) Ruby SDK allows attackers to execute arbitrary JSON-RPC commands and exfiltrate sensitive local data from an MCP server bound to the local loopback interface. This is achieved through DNS-rebinding and cross-origin request execution due to missing validation of the HTTP Host and Origin headers in the StreamableHTTPTransport component.

TL;DR

A DNS-rebinding flaw in the MCP Ruby SDK (< 0.23.0) allows malicious sites to bypass the browser Same-Origin Policy and run arbitrary local tools.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-346, CWE-350
  • Attack Vector: Network (AV:N)
  • CVSS Score: 6.9 (Medium)
  • Exploit Status: PoC Available
  • Affected Component: StreamableHTTPTransport
  • Fixed Version: v0.23.0
  • CISA KEV Status: Not Listed

Affected Systems

  • Model Context Protocol (MCP) Ruby SDK (mcp gem)
  • mcp: < 0.23.0 (Fixed in: v0.23.0)

Code Analysis

Commit: ba54308

Implement DNS rebinding protection in StreamableHTTPTransport by validating Host and Origin headers.

Mitigation Strategies

  • Upgrade the mcp gem to version 0.23.0 or higher.
  • Configure upstream Host and Origin validation in reverse proxies.
  • Restrict server binds strictly to the loopback interface (127.0.0.1 or ::1).

Remediation Steps:

  1. Modify the Gemfile to require 'mcp' version 0.23.0 or higher.
  2. Run 'bundle update mcp' to apply the update.
  3. Optionally define 'allowed_hosts' and 'allowed_origins' parameters if binding to non-loopback interfaces.

References

Read the full report for CVE-2026-63118 on our website for more details including interactive diagrams and full exploit analysis.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.