CVE-2025-10193: Neo4j Cypher MCP server is vulnerable to DNS rebinding attacks

Published Sep 11, 2025
·
Updated

Impact DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.

Patches CORS Middleware added to Cypher MCP server v0.4.0 that blocks all web-based access by default.

Workarounds If you cannot upgrade to v0.4.0 and above, use stdio mode.

References Vendor Advisory https://www.cve.org/CVERecord?id=CVE-2025-10193

Credits We want to publicly recognize the contribution of Evan Harris from mcpsec.dev for reporting this issue and following the responsible disclosure policy.

Other sources

DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally running Neo4j MCP instances. The attack relies on the user being enticed to visit a malicious website and spend sufficient time there for DNS rebinding to succeed.

MITRE

Affected Software

2 affected componentsFixes available
Neo4j Cypher MCP server
pip/mcp-neo4j-cypher>=0.2.2<0.4.0
0.4.0

Remediation

Information

This issue is fixed in v0.4.0 and all later versions.

Event History

Sep 11, 2025
CVE Published
via MITRE·02:05 PM
Data Sourced
via MITRE·02:05 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·11:26 PM
Data Sourced
via GitHub·11:26 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-10193?

CVE-2025-10193 is rated as a high-severity vulnerability due to its potential to allow unauthorized access to Neo4j MCP instances.

2

How can I fix CVE-2025-10193?

To fix CVE-2025-10193, ensure you update your Neo4j Cypher MCP server to the latest patched version.

3

What does CVE-2025-10193 exploit?

CVE-2025-10193 exploits the DNS rebinding vulnerability to bypass Same-Origin Policy protections.

4

Who is affected by CVE-2025-10193?

The vulnerability affects users running Neo4j Cypher MCP server instances.

5

What are the potential impacts of CVE-2025-10193?

The potential impacts of CVE-2025-10193 include unauthorized tool invocations against locally running Neo4j MCP instances.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203