THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81095 (MEDIUM 6.8) — pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named.

[NVD] CVE-2026-81095 (MEDIUM 6.8) — pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named.

mednvdPublished 2026-08-27

CVE-2026-81095 CVSS: 6.8 MEDIUM Published: 2026-08-27T17:20:51.803

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named. A page in a browser could therefore point a name it

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81095