---
id: CVE-2025-9611
title: >-
  Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the
  Origin header on incoming connections
summary: >-
  Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the
  Origin header on incoming connections. This allows an attacker to perform a
  DNS rebinding attack via a victim’s web browser and send unauthorized requests
  to …
severity: none
cwe:
  - CWE-749
published: '2026-01-07'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9611'
references:
  - url: >-
      https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-8rgw-6xp9-2fg3
    label: disclosure@vulncheck.com
  - url: 'https://github.com/microsoft/playwright/commit/1313fbd'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/microsoft-playwright-mcp-server-dns-rebinding-via-missing-origin-header-validation
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0124
epssPercentile: 0.67855
ingestedAt: '2026-07-15T13:44:03.756Z'
---

## Overview

Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
