Critical CVE-2026-11624 Vulnerability in Model Context Protocol
ID: dd0fbe61-f72a-582d-bc36-d4c7bf27ca8b
STIX ID: report--dd0fbe61-f72a-582d-bc36-d4c7bf27ca8b
Feed Name: ThreatCluster
Threat Score
CVE-2026-11624 (published June 13, 2026) is a critical (CVSS 9.4) vulnerability in the Model Context Protocol allowing DNS rebinding attacks by bypassing 'Origin' header validation; users should upgrade to version 0.25.0 or later which adds '--allowed-hosts' and '--allowed-origins' flags to mitigate the issue, and there is currently no public proof-of-concept or evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
