THREAT OPS › Threat News › [GHSA] GHSA-cmwv-wf9p-p8wx (high) — genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
[GHSA] GHSA-cmwv-wf9p-p8wx (high) — genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
GHSA-cmwv-wf9p-p8wx Severity: high CVE: CVE-2026-55637
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
`genieacs-mcp` exposes a local Streamable HTTP MCP endpoint that accepts attacker-controlled `Host` and `Origin` headers. A malicious web page can use DNS rebinding to route browser requests to a victim's loopback MCP listener while preserving the attacker origi
Indicators of compromise
- 4d7d3c74740efb7f3833aadc8a8e9177650eb462sha1
- CVE-2026-55637cve
- https://acs-control.example.invalid/cwmpurl
- http://127.0.0.1:18083url
- http://attacker.example:8083url
- http://127.0.0.1:8080url
Original source: https://github.com/advisories/GHSA-cmwv-wf9p-p8wx