CVE-2026-44968 | dbt-labs dbt-mcp up to 1.17.0 Model Context Protocol tools.py _run_dbt_command os command injection
A vulnerability was found in dbt-labs dbt-mcp up to 1.17.0. It has been classified as critical. This affects the function _run_dbt_command of the file src/dbt_mcp/dbt_cli/tools.py of the component Model Context Protocol. The manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-44968. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More