๐Ÿ” CVE Alert

CVE-2026-77339

UNKNOWN 0.0

Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating the Host header, validating the Origin header, or authenticating the caller. When MCP SSE is enabled, a malicious website can use DNS rebinding to reach the loopback listener and issue MCP requests. If expose_control_tools is enabled, the attacker can enumerate process state, read or search logs, truncate logs, and start, stop, restart, or scale local processes; configured user-defined tools can expose additional commands and output. The Gin REST API token middleware does not protect this separately started MCP listener. This issue is fixed in version 1.120.0.

CWE CWE-306 CWE-346
Vendor f1bonacc1
Product process-compose
Published Sep 18, 2026
Last Updated Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for f1bonacc1 process-compose

Be the first to know when new unknown vulnerabilities affecting f1bonacc1 process-compose are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

F1bonacc1 / process-compose
< 1.120.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v github.com: https://github.com/F1bonacc1/process-compose/commit/6ffa74f462cd2fa4f8dc1ee63c70b793b298c858 github.com: https://github.com/F1bonacc1/process-compose/releases/tag/v1.120.0