DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.
CVSS
No CVSS.
References
Configurations
No configuration.
History
11 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-11 14:15
Updated : 2025-09-11 17:14
NVD link : CVE-2025-10193
Mitre link : CVE-2025-10193
CVE.ORG link : CVE-2025-10193
JSON object : View
Products Affected
No product.
CWE
CWE-346
Origin Validation Error