CVE-2026-77339
— UNSCOREDpublic exploit availablePublished 2026-09-18 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and the returned message endpoint without validating the Host header, validating the Origin header, or authenticating the caller. When MCP SSE is enabled, a malicious website can use DNS rebinding to reach the loopback listener and issue MCP requests. If expose_control_tools is enabled, the attacker can enumerate process state, read or search logs, truncate logs, and start, stop, restart, or scale local processes; configured user-defined tools can expose additional commands and output. The Gin REST API token middleware does not protect this separately started MCP listener. This issue is fixed in version 1.120.0.
Weaknesses
CWE-306, CWE-346
Public exploit & PoC references
- https://github.com/F1bonacc1/process-compose/commit/6ffa74f462cd2fa4f8dc1ee63c70b793b298c858
- https://github.com/F1bonacc1/process-compose/releases/tag/v1.120.0
- https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v
- https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v
All references
- https://github.com/F1bonacc1/process-compose/commit/6ffa74f462cd2fa4f8dc1ee63c70b793b298c858
- https://github.com/F1bonacc1/process-compose/releases/tag/v1.120.0
- https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v
- https://github.com/F1bonacc1/process-compose/security/advisories/GHSA-5gm3-9crp-6g3v
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-61742PoC
- MEDIUMCVE-2026-100192PoC
- HIGHCVE-2026-100598PoC
- HIGHCVE-2026-100642PoC
- HIGHCVE-2026-100646PoC
- HIGHCVE-2026-100672PoC
- HIGHCVE-2026-100746PoC
- MEDIUMCVE-2026-100876PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.