CVE-2025-10193High▾ TwilightNeo4j Cypher MCP server is vulnerable to DNS rebinding
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.
CORS Middleware added to Cypher MCP server v0.4.0 that blocks all web-based access by default.
If you cannot upgrade to v0.4.0 and above, use stdio mode.
Vendor Advisory https://www.cve.org/CVERecord?id=CVE-2025-10193
Credits We want to publicly recognize the contribution of Evan Harris from mcpsec.dev for reporting this issue and following the responsible disclosure policy.
mcp-neo4j-cypher >= 0.2.2, < 0.4.0Upgrade to a patched release:
mcp-neo4j-cypher 0.4.0Connected by shared product, vendor, weakness, or advisory.