Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Dash MCP server DNS rebinding via missing host header validation

The Dash MCP server bound its listener to loopback but failed to validate the Host header, allowing DNS rebinding attacks. A malicious webpage could invoke the server's tools using the visitor's Dropbox credentials.

Disclosed 27 August 2026 · Record updated 13 September 2026

Impact

Remote attackers could invoke company-search and file-detail tools with the local user's Dropbox credentials through DNS rebinding attacks in a web browser.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81102