<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:26:55 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-44969 — dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging I…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-44969</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; dbt-labs dbt-mcp&lt;/p&gt;
&lt;p&gt;dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when DBT_MCP_SERVER_FILE_LOGGING=true, preserving sensitive sql_query, vars, and node_selection values in plaintext without automatic rotation or deletion. This issue is fixed in version 1.17.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; dbt-labs dbt-mcp&lt;/p&gt;
&lt;p&gt;dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when DBT_MCP_SERVER_FILE_LOGGING=true, preserving sensitive sql_query, vars, and node_selection values in plaintext without automatic rotation or deletion. This issue is fixed in version 1.17.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-44969</guid>
    </item>
    <item>
      <title>GHSA-7xgw-6qf3-7w59 — dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Loggi…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7xgw-6qf3-7w59</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: dbt-mcp&lt;/p&gt;
&lt;p&gt;*Discovered through manual source code review. Verified by PoC execution against a local dbt-mcp v1.15.1 installation.*&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`DbtMCP.call_tool()` in `src/dbt_mcp/mcp/server.py` logs the complete raw `arguments` dictionary at `INFO` level on every tool invocation (line 67) and again at `ERROR` level if the call raises an exception (lines 77–79). No field is redacted before logging. When the documented `DBT_MCP_SERVER_FILE_LOGGING=true` feature is enabled, these log records are written to `dbt-mcp.log` in the project root directory as plaintext. Sensitive data — raw SQL queries, `--vars` payloads carrying credentials, node selectors — persists on disk indefinitely with no automatic rotation or deletion.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable log statements (`server.py`):**&lt;/p&gt;
&lt;p&gt;```python
# Line 67 — emitted before every tool execution
logger.info(f&amp;#34;Calling tool: {name} with arguments: {arguments}&amp;#34;)&lt;/p&gt;
&lt;p&gt;# Lines 77–79 — emitted if the tool raises an exception (double-logging on failure)
logger.error(
    f&amp;#34;Error calling tool: {name} with arguments: {arguments} &amp;#34;
    f&amp;#34;in {end_time - start_time}ms: {e}&amp;#34;
)
```&lt;/p&gt;
&lt;p&gt;`arguments` is the raw Python dict received from the MCP client. It is string-interpolated directly into the log message. On a tool call that raises an exception, the same dict is logged twice — once at INFO and once at ERROR.&lt;/p&gt;
&lt;p&gt;File logging is activated by `DBT_MCP_SERVER_FILE_LOGGING=true` (a documented feature in the project README). The log file location is resolved by `configure_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: dbt-mcp&lt;/p&gt;
&lt;p&gt;*Discovered through manual source code review. Verified by PoC execution against a local dbt-mcp v1.15.1 installation.*&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`DbtMCP.call_tool()` in `src/dbt_mcp/mcp/server.py` logs the complete raw `arguments` dictionary at `INFO` level on every tool invocation (line 67) and again at `ERROR` level if the call raises an exception (lines 77–79). No field is redacted before logging. When the documented `DBT_MCP_SERVER_FILE_LOGGING=true` feature is enabled, these log records are written to `dbt-mcp.log` in the project root directory as plaintext. Sensitive data — raw SQL queries, `--vars` payloads carrying credentials, node selectors — persists on disk indefinitely with no automatic rotation or deletion.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable log statements (`server.py`):**&lt;/p&gt;
&lt;p&gt;```python
# Line 67 — emitted before every tool execution
logger.info(f&amp;#34;Calling tool: {name} with arguments: {arguments}&amp;#34;)&lt;/p&gt;
&lt;p&gt;# Lines 77–79 — emitted if the tool raises an exception (double-logging on failure)
logger.error(
    f&amp;#34;Error calling tool: {name} with arguments: {arguments} &amp;#34;
    f&amp;#34;in {end_time - start_time}ms: {e}&amp;#34;
)
```&lt;/p&gt;
&lt;p&gt;`arguments` is the raw Python dict received from the MCP client. It is string-interpolated directly into the log message. On a tool call that raises an exception, the same dict is logged twice — once at INFO and once at ERROR.&lt;/p&gt;
&lt;p&gt;File logging is activated by `DBT_MCP_SERVER_FILE_LOGGING=true` (a documented feature in the project README). The log file location is resolved by `configure_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7xgw-6qf3-7w59</guid>
    </item>
  </channel>
</rss>
