Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Nhost CLI MCP server lacked authentication and CORS enforcement (CVE-2026-34200)

Prior to version 1.41.0, the Nhost CLI MCP server applied no inbound authentication and did not enforce strict CORS when explicitly configured to listen on a network port, letting a malicious website invoke privileged MCP tools with the developer's local credentials. Exploitation required two non-default configuration steps; the issue was patched in version 1.41.0.

Disclosed 31 March 2026 · Record updated 13 September 2026

Impact

A malicious website visited on the same machine could issue cross-origin requests to the locally running MCP server and invoke privileged tools using the developer's configured credentials.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34200