CVE-2026-44970 | dbt-labs dbt-mcp up to 1.17.0 Usage Tracker tracking.py DefaultUsageTracker.emit_tool_called_event sql_query/vars/build/test/node_selection deserialization
A vulnerability was found in dbt-labs dbt-mcp up to 1.17.0. It has been declared as problematic. This vulnerability affects the function DefaultUsageTracker.emit_tool_called_event of the file src/dbt_mcp/tracking/tracking.py of the component Usage Tracker. The manipulation of the argument sql_query/vars/build/test/node_selection results in deserialization.
This vulnerability is reported as CVE-2026-44970. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More