dbt-mcp vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55837Mediumdbt-mcp: dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform TokensCVE-2026-44970Lowdbt-mcp: dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without RedactionCVE-2026-44969Lowdbt-mcp: dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is EnabledCVE-2026-44968Mediumdbt-mcp: dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

Stop the waste.
Protect your environment with Kodem.