MCP Ruby SDK DNS Rebinding via Missing Host/Origin Validation in StreamableHTTPTransport
highAgentProtocol VulnerabilityThe MCP Ruby SDK's HTTP transport failed to validate Host or Origin headers before version 0.23.0, allowing a malicious website to use DNS rebinding to reach a locally running MCP server from a victim's browser. This lets an attacker invoke tools exposed by the local MCP server without authorization, effectively bypassing the same-origin trust boundary that localhost services normally rely on.
Updated Jul 30, 2026