Dash MCP server DNS rebinding via missing host header validation
The Dash MCP server bound its listener to loopback but failed to validate the Host header, allowing DNS rebinding attacks. A malicious webpage could invoke the server's tools using the visitor's Dropbox credentials.
Disclosed 27 August 2026 · Record updated 13 September 2026
Impact
Remote attackers could invoke company-search and file-detail tools with the local user's Dropbox credentials through DNS rebinding attacks in a web browser.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81102
