Executive brief
dbt-mcp is a tool that allows users to interact with dbt (data build tool) through the Model Context Protocol. A security flaw in how it handles user input allows an attacker to inject unauthorized commands or configuration flags when the tool runs dbt in the background. This could allow an attacker to redirect data processing to malicious locations or gain unauthorized access to sensitive database configurations.
Technical details
An argument injection vulnerability (CWE-88) exists in dbt-mcp's `_run_dbt_command()` function within `src/dbt_mcp/dbt_cli/tools.py`. The application fails to sanitize the `node_selection` and `resource_type` parameters before appending them to the argument list for `subprocess.Popen`. While `shell=False` is used, the lack of validation allows an attacker to provide strings starting with hyphens (e.g., `--profiles-dir` or `--target`), which the underlying dbt process interprets as global flags rather than positional arguments. This can be exploited by a local attacker to point dbt to a malicious configuration file, potentially leading to arbitrary code execution or data exfiltration via malicious database drivers. The issue is fixed in version 1.17.1 by validating that input tokens do not start with dashes and verifying resource types against an allowlist.
Affected products
- dbt-labs dbt-mcp < 1.17.1
Timeline
- 2026-05-05: patched: Fix committed and version 1.17.1 released.
- 2026-05-13: advisory: GitHub Security Advisory GHSA-xpww-f6pm-cfhq published.
- 2026-07-16: disclosed: CVE-2026-44968 published to NVD.