Neo4j Cypher MCP server is vulnerable to DNS rebinding attacks
Vulnerability Description
DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10193
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Evan Harris
References
More from neo4j
View All →Affected Vendor
neo4j
View all reports →