CVE-2025-10193
HIGHNeo4j Cypher MCP server 0.2.2-0.3.0 - DNS Rebinding Attack via Same-Origin Policy Bypass
Title source: llmDescription
DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.
References (3)
Core 3
Core References
Release Notes release-notes
https://github.com/neo4j-contrib/mcp-neo4j/releases/tag/mcp-neo4j-cypher-v0.4.0
Various Sources vendor-advisory
https://neo4j.com/security/cve-2025-10193
Vendor Advisory third-party-advisory
https://github.com/neo4j-contrib/mcp-neo4j/security/advisories/GHSA-vcqx-v2mg-7chx
Scores
CVSS v4
7.4
EPSS
0.0021
EPSS Percentile
10.6%
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/V:D/RE:L/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-346
Status
published
Products (2)
neo4j/neo4j-cypher MCP server
0.2.2 - 0.3.1
pypi/mcp-neo4j-cypher
0.2.2 - 0.4.0PyPI
Published
Sep 11, 2025
Tracked Since
Feb 18, 2026