Junglewise Threat Intelligence

nubo-db dynoxide DNS rebinding and CSRF in MCP HTTP transport

Severity: high · CVSS 7.5 · Published 2026-05-18

Vendors: npm, crates.io.

Executive brief

Dynoxide, a DynamoDB-compatible database engine, is vulnerable to an attack that allows malicious websites to interact with a locally running database instance. If a user visits a compromised website while running Dynoxide with the HTTP transport enabled, an attacker could read, modify, or delete any data stored in the database. This could lead to significant data loss or unauthorized exposure of sensitive information.

Technical details

Dynoxide's Model Context Protocol (MCP) HTTP transport is vulnerable to DNS rebinding and Cross-Site Request Forgery (CSRF). The DNS rebinding vulnerability stems from a transitive dependency on `rmcp` (prior to v1.4.0), which failed to validate the `Host` header, allowing a malicious site to bypass the Same-Origin Policy. Additionally, a lack of `Origin` header validation allowed CSRF attacks via `no-cors` fetch requests. An attacker can exploit these by tricking a user into visiting a malicious webpage, which then sends unauthorized requests to the local Dynoxide server (typically running on a loopback address). This grants the attacker full access to MCP tools, including data retrieval and modification commands. The issue is fixed in version 0.9.13 by upgrading `rmcp` and implementing explicit Host and Origin allowlists.

Affected products

  • nubo-db dynoxide-rs >= 0.9.3, < 0.9.13
  • nubo-db dynoxide >= 0.9.3, < 0.9.13

Timeline

  • 2026-05-11: disclosed: Vulnerability identified via Dependabot and published to repository
  • 2026-05-11: patched: Version 0.9.13 released
  • 2026-05-18: advisory: GitHub Advisory published

References

Related threats