CVE-2025-10193

HIGH

Pypi Mcp-neo4j-cypher < 0.4.0 - Origin Validation Error

Title source: rule
STIX 2.1

Description

DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.

Scores

CVSS v4 7.4
EPSS 0.0002
EPSS Percentile 6.3%
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/V:D/RE:L/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-346
Status published
Products (2)
neo4j/neo4j-cypher MCP server 0.2.2 - 0.3.1
pypi/mcp-neo4j-cypher 0.2.2 - 0.4.0PyPI
Published Sep 11, 2025
Tracked Since Feb 18, 2026