GHSA-v3f4-w7r7-v3hmHigh▾ TwilightUni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Uni-CLI versions before 0.225.2 exposed the legacy JSON-RPC-over-HTTP MCP transport on loopback without validating browser Origin headers before routing requests. A malicious web page could send a CORS simple POST request, such as text/plain, to the local /mcp endpoint and deliver a JSON-RPC body to the dispatcher. If the user had started the local MCP HTTP transport, that page could drive tools/call requests against the user's local Uni-CLI server.
The Streamable HTTP transport already enforced this browser-to-localhost boundary. The legacy stateless HTTP path did not, so the two HTTP transports had drifted. This issue is about the browser-to-localhost boundary; it does not change Uni-CLI's local-code-execution trust model.
Version 0.225.2 fixes the issue by moving the Origin policy into a shared guard and applying it before routing in both HTTP transports. Non-loopback browser Origins are rejected with HTTP 403 before health, OAuth, or /mcp dispatch runs. Non-browser clients that omit Origin remain supported.
Upgrade to 0.225.2 or later. If upgrading is not immediately possible, do not expose the legacy HTTP MCP transport to browser-originated traffic; use the default stdio transport or the Streamable HTTP transport instead.
Reported privately by Ryan Vonbrubeck (@dodge1218).
@zenalexa/unicli < 0.225.2Upgrade to a patched release:
@zenalexa/unicli 0.225.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46409Critical· 9.6OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top
CVE-2026-50025Medium· 6.9Mousehole is a background service to update a seedbox IP for MAM and web app to manage it
CVE-2026-19418HighTYPO3 CMS - Broken Access Control in Backend and Install Tool
CVE-2026-55532High· 7.6PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…
CVE-2017-20120Medium· 4.3A vulnerability classified as problematic was found in TrueConf Server 4.3.7
CVE-2024-0830Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0