CVE-2025-9611: DNS rebinding in Microsoft Playwright MCP Server via missing Origin check
Microsoft Playwright MCP Server versions before 0.0.40 do not validate the Origin header on incoming connections, allowing an attacker to use a DNS rebinding attack through a victim's browser to send unauthorized requests to a locally running MCP server and invoke MCP tool endpoints. The issue is addressed in version 0.0.40.
Disclosed 7 January 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers could trigger unintended invocation of MCP tool endpoints on a locally running Playwright MCP server via a victim's web browser.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-9611
