VYPR

Tiger Slack

by Timescale

CVEs (1)

  • CVE-2026-81099MedAug 27, 2026
    risk 0.37cvss 6.8epss

    tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it…