THREAT OPS › Threat News › [NVD] CVE-2026-81095 (MEDIUM 6.8) — pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named.
[NVD] CVE-2026-81095 (MEDIUM 6.8) — pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named.
CVE-2026-81095 CVSS: 6.8 MEDIUM Published: 2026-08-27T17:20:51.803
pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named. A page in a browser could therefore point a name it
Indicators of compromise
- CVE-2026-81095cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81095