CVE-2025-10193

DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Sep 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-11 14:15

Updated : 2025-09-11 17:14


NVD link : CVE-2025-10193

Mitre link : CVE-2025-10193

CVE.ORG link : CVE-2025-10193


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error