VYPR

Dbt Mcp

by Dbt Labs

Source repositories

CVEs (4)

  • CVE-2026-44968MedJul 16, 2026
    risk 0.41cvss 6.3epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the dbt subprocess argument list, allowing an MCP client to inject dbt global…

  • CVE-2026-55837MedSep 14, 2026
    risk 0.37cvss 6.8epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The…

  • CVE-2026-44969LowJul 16, 2026
    risk 0.16cvss 2.5epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote…

  • CVE-2026-44970LowJul 16, 2026
    risk 0.13cvss 3.1epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent it through…