Executive brief
The MCP Toolbox for Databases is a server that provides database access to AI agents via the Model Context Protocol. Prior to version 0.25.0, it failed to validate the Origin and Host headers on incoming requests, allowing attackers to exploit DNS rebinding attacks. An attacker could trick a user into visiting a malicious website, which would then gain full remote control over the user's locally running MCP Toolbox server, enabling database manipulation, data theft, and unauthorized resource creation.
Technical details
This vulnerability is a DNS rebinding attack arising from insufficient Origin and Host header validation (CWE-346). The MCP Toolbox HTTP server, by default in versions prior to 0.25.0, accepted requests from any origin and did not validate the Host header. This allowed an attacker to craft a malicious website that, via DNS rebinding, initially resolves to an attacker-controlled server to load JavaScript, then rebinds to localhost to issue cross-origin requests to the victim's local MCP Toolbox instance. Since the Origin header was not validated, the server accepted these requests. The attack requires user interaction (visiting a malicious site) but then grants the attacker network-level access to the locally running service. Version 0.25.0 remediated this by introducing --allowed-hosts and --allowed-origins configuration flags; however, both default to "*" to avoid breaking existing deployments, and servers output a startup warning if either remains permissive.
Affected products
- Google MCP Toolbox for Databases < 0.25.0
Timeline
- 2026-06-13: disclosed: Published to GitHub Advisory Database
- 2026-01-08: patched: Fix released in v0.25.0 with --allowed-hosts and --allowed-origins flags