Origin validation error in ash_ai MCP server allows DNS rebinding attacks
A vulnerability in ash_ai's MCP server allows malicious web pages to bypass DNS-rebinding protection through improper origin validation, enabling cross-site requests to local MCP servers. The issue affects versions 0.8.0 before 1.0.0 and has been fixed by trusting only localhost origins by default.
Disclosed 31 August 2026 · Record updated 13 September 2026
Impact
Malicious web pages can bypass DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor privileges.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81315
