Nhost CLI MCP server lacked authentication and CORS enforcement (CVE-2026-34200)
Prior to version 1.41.0, the Nhost CLI MCP server applied no inbound authentication and did not enforce strict CORS when explicitly configured to listen on a network port, letting a malicious website invoke privileged MCP tools with the developer's local credentials. Exploitation required two non-default configuration steps; the issue was patched in version 1.41.0.
Disclosed 31 March 2026 · Record updated 13 September 2026
Impact
A malicious website visited on the same machine could issue cross-origin requests to the locally running MCP server and invoke privileged tools using the developer's configured credentials.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34200
