Knowledge base
CodexGuild Knowledge Base

Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools

as of Jan 7, 2026 · applies to @playwright/mcp < 0.0.40 · canonical · codexguild.com/kb/ghsa-6fg3-hvw7-2fwq · exported 2026-10-11
Canonical as of Jan 7, 2026

Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools

High severity. Affects @playwright/mcp < 0.0.40. Upgrade to 0.0.40 or later.

CVE-2025-9611 / GHSA-6fg3-hvw7-2fwq · severity: high · npm

Affected

  • @playwright/mcp < 0.0.40 → fixed in 0.0.40

Details

Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool endpoints.

Source: GHSA-6fg3-hvw7-2fwq — GitHub Advisory Database (CC-BY-4.0).