logo

Critical CVE-2026-11624 Vulnerability in Model Context Protocol

ID: dd0fbe61-f72a-582d-bc36-d4c7bf27ca8b

STIX ID: report--dd0fbe61-f72a-582d-bc36-d4c7bf27ca8b

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-14

Date Updated: 2026-06-14

...
...

CVE-2026-11624 (published June 13, 2026) is a critical (CVSS 9.4) vulnerability in the Model Context Protocol allowing DNS rebinding attacks by bypassing 'Origin' header validation; users should upgrade to version 0.25.0 or later which adds '--allowed-hosts' and '--allowed-origins' flags to mitigate the issue, and there is currently no public proof-of-concept or evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.