Junglewise Threat Intelligence

CVE-2026-81095: pg-aiguide DNS rebinding vulnerability in MCP HTTP transport

CVE-2026-81095 · Severity: medium · CVSS 6.8 · Published 2026-08-27

Executive brief

pg-aiguide is a PostgreSQL assistant tool that exposes a local MCP (Model Context Protocol) HTTP server for AI coding assistants. The vulnerability allows an attacker to make a victim's browser send requests to the local server through DNS rebinding, bypassing the host validation protections that should prevent this attack. This could enable unauthorized access to the PostgreSQL server's capabilities through the victim's authenticated session.

Technical details

The vulnerability is a DNS rebinding attack in the MCP HTTP transport implementation. The src/httpServer.ts file failed to enable the dnsRebindingProtection option when calling the httpServerFactory helper from the underlying @tigerdata/mcp-boilerplate SDK, which left the server vulnerable to host header spoofing. An attacker could craft a malicious webpage that uses DNS rebinding techniques to make the victim's browser reach the locally-bound MCP server with an arbitrary Host header, bypassing origin validation. The protection mechanism was available in the SDK but simply not enabled in the application configuration. The fix was to explicitly set dnsRebindingProtection: !isProduction in the httpServer.ts configuration, which was released in version 0.5.1.

Affected products

  • Timescale pg-aiguide before 0.5.1

Timeline

  • 2026-08-27: disclosed
  • 2026-06-26: patched: Fixed in version 0.5.1 via PR #121

References