<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:01:01.745741+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338569</id>
    <title>EUVD-2026-338569</title>
    <updated>2026-10-03T14:01:01.813093+00:00</updated>
    <content>EUVD-2026-338569</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44969</id>
    <title>fkie_cve-2026-44969</title>
    <updated>2026-10-03T14:01:01.813130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when DBT_MCP_SERVER_FILE_LOGGING=true, preserving sensitive sql_query, vars, and node_selection values in plaintext without automatic rotation or deletion. This issue is fixed in version 1.17.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7xgw-6qf3-7w59</id>
    <title>GHSA-7xgw-6qf3-7w59 — dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Loggi…</title>
    <updated>2026-10-03T14:01:01.813165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: dbt-mcp</p>
<p>*Discovered through manual source code review. Verified by PoC execution against a local dbt-mcp v1.15.1 installation.*</p>
<p>### Summary</p>
<p>`DbtMCP.call_tool()` in `src/dbt_mcp/mcp/server.py` logs the complete raw `arguments` dictionary at `INFO` level on every tool invocation (line 67) and again at `ERROR` level if the call raises an exception (lines 77–79). No field is redacted before logging. When the documented `DBT_MCP_SERVER_FILE_LOGGING=true` feature is enabled, these log records are written to `dbt-mcp.log` in the project root directory as plaintext. Sensitive data — raw SQL queries, `--vars` payloads carrying credentials, node selectors — persists on disk indefinitely with no automatic rotation or deletion.</p>
<p>### Details</p>
<p>**Vulnerable log statements (`server.py`):**</p>
<p>```python
# Line 67 — emitted before every tool execution
logger.info(f"Calling tool: {name} with arguments: {arguments}")</p>
<p># Lines 77–79 — emitted if the tool raises an exception (double-logging on failure)
logger.error(
    f"Error calling tool: {name} with arguments: {arguments} "
    f"in {end_time - start_time}ms: {e}"
)
```</p>
<p>`arguments` is the raw Python dict received from the MCP client. It is string-interpolated directly into the log message. On a tool call that raises an exception, the same dict is logged twice — once at INFO and once at ERROR.</p>
<p>File logging is activated by `DBT_MCP_SERVER_FILE_LOGGING=true` (a documented feature in the project README). The log file location is resolved by `configure_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7xgw-6qf3-7w59"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2441</id>
    <title>PYSEC-2026-2441 — dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Loggi…</title>
    <updated>2026-10-03T14:01:01.813236+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: dbt-mcp</p>
<p>*Discovered through manual source code review. Verified by PoC execution against a local dbt-mcp v1.15.1 installation.*</p>
<p>### Summary</p>
<p>`DbtMCP.call_tool()` in `src/dbt_mcp/mcp/server.py` logs the complete raw `arguments` dictionary at `INFO` level on every tool invocation (line 67) and again at `ERROR` level if the call raises an exception (lines 77–79). No field is redacted before logging. When the documented `DBT_MCP_SERVER_FILE_LOGGING=true` feature is enabled, these log records are written to `dbt-mcp.log` in the project root directory as plaintext. Sensitive data — raw SQL queries, `--vars` payloads carrying credentials, node selectors — persists on disk indefinitely with no automatic rotation or deletion.</p>
<p>### Details</p>
<p>**Vulnerable log statements (`server.py`):**</p>
<p>```python
# Line 67 — emitted before every tool execution
logger.info(f"Calling tool: {name} with arguments: {arguments}")</p>
<p># Lines 77–79 — emitted if the tool raises an exception (double-logging on failure)
logger.error(
    f"Error calling tool: {name} with arguments: {arguments} "
    f"in {end_time - start_time}ms: {e}"
)
```</p>
<p>`arguments` is the raw Python dict received from the MCP client. It is string-interpolated directly into the log message. On a tool call that raises an exception, the same dict is logged twice — once at INFO and once at ERROR.</p>
<p>File logging is activated by `DBT_MCP_SERVER_FILE_LOGGING=true` (a documented feature in the project README). The log file location is resolved by `configure_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2441"/>
  </entry>
</feed>
