dbt-mcp
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting dbt-mcppage 1 of 1
- CVE-2026-44968MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.17.12026-07-16
vulnerable: 0.0.1a1 ... 1.9.3 (69 versions)
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the dbt subprocess argument list, allo…
- CVE-2026-44969LOWCVSS 3.3EG 3.3✓ Fixed in 1.17.12026-07-16
vulnerable: 0.0.1a1 ... 1.9.3 (69 versions)
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions,…
- CVE-2026-44970MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.17.12026-07-16
vulnerable: 0.0.1a1 ... 1.9.3 (69 versions)
dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent …
- CVE-2026-55837MEDIUMCVSS 6.8EG 6.8✓ Fixed in 1.20.02026-06-19
vulnerable: 0.0.1a1 ... 1.9.3 (75 versions)
dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens ## Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens ### Summary The local OAuth helper FastAPI server bundled with `dbt-mcp` exposes the `G…
Check whether dbt-mcp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for dbt-mcp CVEs against the assets you own.
Start Free Scan →