<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:59:36.202938+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-44968</id>
    <title>CVE-2026-44968 — dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters</title>
    <updated>2026-10-03T13:59:36.233543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> dbt-labs dbt-mcp</p>
<p>dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the dbt subprocess argument list, allowing an MCP client to inject dbt global flags such as --profiles-dir, --project-dir, and --target into subprocess.Popen even though shell=False prevents shell metacharacter injection. This issue is fixed in version 1.17.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-44968"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xpww-f6pm-cfhq</id>
    <title>GHSA-xpww-f6pm-cfhq — dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters</title>
    <updated>2026-10-03T13:59:36.233603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: dbt-mcp</p>
<p>*Discovered through manual source code review. Verified by PoC execution against a local dbt-mcp v1.15.1 installation.**</p>
<p>## Summary</p>
<p>`_run_dbt_command()` in `src/dbt_mcp/dbt_cli/tools.py` constructs the dbt subprocess argument list by appending user-supplied MCP tool parameters without sanitization. Two independent injection vectors exist. An MCP client can inject arbitrary dbt global flags — such as `--profiles-dir`, `--project-dir`, and `--target` — by crafting the `node_selection` string (Vector 1) or the `resource_type` JSON array (Vector 2). Because `subprocess.Popen` is called with `shell=False` and a list argument, shell metacharacter injection is not possible; however, this provides no defense against argument list injection (CWE-88), where attacker-controlled tokens are interpreted by the target process as flags rather than values.</p>
<p>## Details</p>
<p>**Vector 1 — `node_selection` string**
Affected tools: `build`, `compile`, `run`, `test`, `clone`, `list`, `get_node_details_dev`</p>
<p>```python
# src/dbt_mcp/dbt_cli/tools.py  lines 77–79
if node_selection and isinstance(node_selection, str):
    selector_params = node_selection.split(" ")
    command.extend(["--select"] + selector_params)
```</p>
<p>`str.split(" ")` does not distinguish dbt selector tokens from flag tokens. Input `"my_model --profiles-dir /tmp/evil"` produces:</p>
<p>````
["dbt", "--no-use-colors", "run",
 "--select", "my_model", "--profiles-dir", "/tmp/evil"]
````</p>
<p>dbt parses the injected `--profiles-dir` as a global opt…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xpww-f6pm-cfhq"/>
  </entry>
</feed>
