securityonline.info 5/31/2026, 4:41:16 PM · external

CVE-2026-0257 flaw in MCP Toolbox allows site based session hijack

CVE-2026-0257 flaw in MCP Toolbox allows site based session hijack
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Listed in KEV
Patch Patch Available

A critical vulnerability (CVE-2026-0257) has been identified in the MCP Toolbox, affecting its integration with enterprise database connectors. This flaw allows malicious websites to bypass security controls, exposing networks to session hijacking risks. The underlying issue stems from a hardcoded access control header that overrides CORS policies, enabling unauthorized access to local servers. The recommended fix involves removing the problematic header to restore secure origin permissions, thereby protecting sensitive infrastructure.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline