CVE-2025-66416 describes a DNS rebinding vulnerability in the MCP Python SDK (mcp on PyPI) prior to version 1.23.0. This flaw affects HTTP-based MCP servers running on localhost without authentication, specifically when using FastMCP with streamable HTTP or SSE transport and without configured TransportSecuritySettings. A malicious website could exploit this to bypass same-origin policy, allowing an attacker to invoke tools or access resources on the local MCP server on behalf of the user. The vulnerability has a HIGH severity CVSS score of 7.6, indicating a network-based attack with low complexity that requires user interaction, potentially leading to high confidentiality and integrity impacts. While the EPSS score is low, the FAUCET Risk Score is 85/100, highlighting its potential risk under specific conditions. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.23.0CPE matchmatch criteria | cpe:2.3:a:lfprojects:mcp_python_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.