
CVE-2026-55837: dbt MCP Server OAuth context endpoint leaks dbt Platform tokens The advisory describes a local OAuth helper FastAPI server in dbt-mcp exposing GET /dbtplatformcontext without authentication or host/origin validation, allowing retrieval of dbt Platform tokens via that endpoint. #MCP #AgentSecurity #AISecurity #Advisory http://www.cyberpocket.org https://github.com/advisories/GHSA-jr33-mw75-7j8f
Post summary
The advisory announces CVE-2026-55837, detailing a missing authentication flaw that allows token retrieval via a specific endpoint. No exploit code, active exploitation, or patches are mentioned.
