CWE-350

CWE-350 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-350, highest CVSS first.

  1. CRITICAL 9.6CVE-2026-61568public PoC

    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a vict…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.1CVE-2026-97875public PoC

    Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() …

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.3CVE-2026-61743public PoC

    Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's server/modules/safeRequest.js calls validateOutboundUrl() to resolve and validate a target hostname, but …

    AI risk analysis on Exploit-DB.ai →