DNS Rebinding Vulnerability in Timescale MCP Tools
Timescale's pg-aiguide and tiger-slack failed to enable DNS rebinding protection in their MCP HTTP transports, allowing attackers to drive locally reachable servers through a visitor's browser via DNS name control.
Disclosed 27 August 2026 · Record updated 13 September 2026
Impact
Remote attackers could exploit DNS rebinding to access and control locally reachable MCP servers through a browser, potentially compromising systems running these tools.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81095
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81099
