Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Node.js & npm GHSA-fm8p-53ww-hf6w CVE-2026-61742 GHSA-mwwr-p57h-56pf CVE-2026-61788

Two DBHub Vulnerabilities Allow Unauthenticated Access and Read-Only Bypass

DBHub, a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB and SQLite, had two flaws in its HTTP transport mode: a DNS-rebinding bypass of its origin check (CVE-2026-61742) and a read-only enforcement bug that still allows writes and, in privileged setups, remote code execution (CVE-2026-61788). Both are fixed in updated DBHub releases.

AI summary

DBHub is a database MCP (Model Context Protocol) server that bridges AI tools and agents to databases including Postgres, MySQL, SQL Server, Oracle, MariaDB, and SQLite. Two vulnerabilities have been disclosed affecting DBHub's optional HTTP transport mode, both tracked with CVEs and fixed in subsequent releases. The first allows a malicious website to bypass DBHub's origin-based access control via DNS rebinding and invoke MCP tools without authentication. The second concerns a `readonly` flag on the `execute_sql` tool that does not actually enforce read-only database access, which can be abused to tamper with data or, in privileged configurations, achieve remote code execution. This briefing covers both issues together since they affect the same product and transport mode.

What happened

Two separate vulnerabilities were disclosed in DBHub's HTTP transport mode (started with options such as `--transport http --port 8080`). CVE-2026-61742 (GHSA-fm8p-53ww-hf6w): DBHub's HTTP server tries to restrict browser-origin access by checking that the `Origin` header's hostname matches the `Host` header's hostname, then reflects the validated `Origin` into the `Access-Control-Allow-Origin` response header. This check does not protect against DNS rebinding. Once an attacker-controlled hostname is rebound to point at a victim-accessible DBHub HTTP server, both `Origin` and `Host` can contain the same attacker-controlled hostname, so DBHub accepts the request. This lets a malicious website invoke DBHub MCP tools directly from the victim's browser, with no prompt injection or AI model involvement required. Against the default demo configuration this can read and write the demo SQLite database; against a real configured database, the same technique can read, enumerate, and potentially write data, depending on DBHub's configured tool permissions and database credentials. CVE-2026-61788 (GHSA-mwwr-p57h-56pf): The `execute_sql` tool accepts a `readonly = true` setting, but this setting does not make the underlying database connection read-only. The connector code that should set PostgreSQL's `default_transaction_read_only=on` (or open SQLite in read-only mode) is gated behind a configuration value that is never populated, so it never executes. The only remaining enforcement is a classifier that inspects the first keyword of a SQL statement, which can be bypassed by any `SELECT` statement that triggers writes or side effects through a function call.

Technical cause

CVE-2026-61742 is a Missing Authentication for Critical Function issue (CWE-306): the origin-matching logic used for CORS/CSRF-style protection can be satisfied by an attacker through DNS rebinding, since both the `Host` and `Origin` headers can be made to reflect an attacker-controlled hostname once DNS resolution is manipulated. CVE-2026-61788 is classified as Incomplete List of Disallowed Inputs (CWE-184): the read-only enforcement relies on a simple first-keyword classifier for SQL statements rather than actually configuring the database connection as read-only, and the intended connector-level read-only setting is never applied due to a configuration gating bug. A `SELECT` statement that calls a function with side effects (such as `lo_export` or `pg_read_file` on PostgreSQL, or using `dblink` combined with `COPY ... TO PROGRAM`) passes the classifier while still writing data or executing commands.

Why it matters

Both vulnerabilities affect DBHub's HTTP transport, which the advisories note is unauthenticated by default and, per CVE-2026-61788, binds to `0.0.0.0` by default — meaning it is reachable by any network caller that can reach the `/mcp` endpoint. For CVE-2026-61742, the impact ranges from reading/writing a default demo SQLite database to reading, enumerating, and potentially writing a real production database, depending on configured tool permissions and credentials — all triggerable from a victim's browser visiting a malicious website, with no user interaction beyond that visit and no involvement of the AI model itself. For CVE-2026-61788, the impact depends on the privilege level of the configured database role: with an ordinary role, it allows sequence tampering; with a privileged PostgreSQL role, the advisory states it can allow writing arbitrary files to the server (`lo_export`), reading arbitrary host files (`pg_read_file`), and remote code execution via `dblink` combined with `COPY ... TO PROGRAM`.

Who is affected

Any deployment of the `@bytebase/dbhub` npm package running the HTTP transport mode is affected. CVE-2026-61742 affects versions up to and including 0.22.4. CVE-2026-61788 affects versions prior to 0.22.6. Deployments using only the default/stdio transport, or that have already upgraded past the fixed versions, are not affected by the respective issue.

Affected versions

@bytebase/dbhub: - CVE-2026-61742: versions from 0 up to and including 0.22.4 are affected; fixed in 0.22.5. - CVE-2026-61788: versions from 0 up to (but not including) 0.22.6 are affected; fixed in 0.22.6.

Fixes and mitigation

The DNS-rebinding origin-check bypass (CVE-2026-61742) is fixed in version 0.22.5 of @bytebase/dbhub. The read-only enforcement bug (CVE-2026-61788) is fixed in version 0.22.6. Upgrading to 0.22.6 addresses both issues, since it is a later release than 0.22.5.

Recommended action

Upgrade @bytebase/dbhub to version 0.22.6 or later, which includes the fixes for both CVE-2026-61742 and CVE-2026-61788. Until upgraded, operators running DBHub's HTTP transport should avoid exposing it to untrusted networks or browsers, and should not rely on the `readonly` flag on `execute_sql` as a security boundary. Review configured database role privileges, since the impact of CVE-2026-61788 is significantly worse when DBHub is configured with a privileged database account.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 9.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

CVE-2026-61742 carries a CVSS v4.0 base score of 9.3, reflecting network-exploitable, low-complexity, no-privilege, no-user-interaction access with high impact to confidentiality, integrity, and availability of the affected component. CVE-2026-61788 carries a CVSS v3.1 base score of 7.4, reflecting network exploitability with high attack complexity but no privileges or user interaction required, and high confidentiality and integrity impact. The computed PatchBriefing scores (5.9 and 4.9 respectively) incorporate the CVSS base score plus additional factors: both issues are reachable without authentication over the network and require no user interaction, which increases their score contribution; neither is currently known to be exploited in the wild or to have public exploit code, and both have fixes available, which keeps the overall scores from being higher. No EPSS score was available for either CVE's primary record at the time of this briefing (EPSS values of 0.002 and 0.003 appear only in the underlying advisory claims data, not as top-level EPSS scores).

Affected versions

@bytebase/dbhub <= 0.22.4
vulnerable
≥ 0.22.5
patched
@bytebase/dbhub < 0.22.6
vulnerable
≥ 0.22.6
patched

Reported fixes

The DNS-rebinding origin-check bypass (CVE-2026-61742) is fixed in version 0.22.5 of @bytebase/dbhub. The read-only enforcement bug (CVE-2026-61788) is fixed in version 0.22.6. Upgrading to 0.22.6 addresses both issues, since it is a later release than 0.22.5.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Two DBHub Vulnerabilities Allow Unauthenticated Access and Read-Only Bypass
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email