EXECUTIVE SUMMARY:
The @bytebase/dbhub package contains two vulnerabilities affecting its database access controls. One is a DNS rebinding vulnerability in the HTTP transport that allows a malicious website to bypass browser-origin protections and invoke unauthenticated MCP tools potentially enabling database enumeration data theft and database modification. The other affects read-only enforcement because the database-level restriction is not properly applied and the SQL classifier can be bypassed using function calls allowing unauthorized database writes and potentially file access or remote code execution when privileged database credentials are configured.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
The @bytebase/dbhub package contains two vulnerabilities affecting its database access controls. One is a DNS rebinding vulnerability in the HTTP transport that allows a malicious website to bypass browser-origin protections and invoke unauthenticated MCP tools potentially enabling database enumeration data theft and database modification. The other affects read-only enforcement because the database-level restriction is not properly applied and the SQL classifier can be bypassed using function calls allowing unauthorized database writes and potentially file access or remote code execution when privileged database credentials are configured.[emaillocker id="1283"]
CVE-2026-61742 (CVSS 9.3 — Critical): DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution, enabling a malicious website to invoke DBHub MCP tools from the victim's browser without prompt injection or model involvement.
CVE-2026-61788 (CVSS 7.4 — High): A read-only enforcement vulnerability in @bytebase/dbhub allows SQL statements using function calls to bypass the read-only classifier and perform database writes. With privileged database credentials this can further enable arbitrary file access and potentially remote code execution.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-fm8p-53ww-hf6w
https://github.com/advisories/GHSA-mwwr-p57h-56pf