Executive brief
tiger-gh-mcp-server is a GitHub API wrapper for AI agents that exposes an HTTP endpoint to run locally. The server failed to validate the Host header on incoming requests, allowing an attacker to trigger requests from a victim's browser pointing to the local server via DNS rebinding, potentially allowing unauthorized access to the GitHub API credentials running locally.
Technical details
The vulnerability is a DNS rebinding attack enabled by missing Host header validation in the HTTP MCP transport. The httpServer.ts file called httpServerFactory without enabling the dnsRebindingProtection option provided by the underlying SDK, which implements a Host allow-list to restrict requests to localhost addresses. An attacker could register a domain, point it at 127.0.0.1, and trick a victim into visiting a malicious page that makes requests to that domain, which would be accepted by the unauthenticated local MCP server. The fix explicitly enables dnsRebindingProtection alongside a dependency update; the dependency update alone was insufficient. This affects all commits before the fix was merged (PR #36 on June 26, 2026).
Affected products
- TimescaleDB tiger-gh-mcp-server before PR #36 merge (June 26, 2026)
Timeline
- 2026-08-27: disclosed: CVE-2026-81100 published
- 2026-06-26: patched: PR #36 merged with DNS rebinding protection fix