What happened
Imperva researchers identified and reported a critical issue in version 1.1.4 (90-day disclosure, published 2026-09-25): chain = missing host/origin validation (DNS rebinding) + stateless MCP session (cross-origin requests accepted) + start_debugging UNC path execution = background RCE from a malicious webpage. The maintainers patched via commit 86776b2 shipped silently; fixed in 1.2.0+.
Why it matters
DebugMCP is a canonical 'agent tool gets code execution' case: a popular AI coding-assistant extension wires a debugger (a file-execution primitive) to a local unauthenticated HTTP server that any website can reach via DNS rebinding. It shows MCP servers still ship without the origin-validation defense-in-depth the ecosystem began adding in 2025, and that a single drive-by request can yield full user-context code execution on AI developer workstations. Update to 1.2.0+ and avoid exposing MCP debugger servers beyond localhost.
Attack vector
The custom Express server lacks the host/origin validation middleware (like CVE-2025-53967/Anthropic's DNS-rebinding default), so a website can DNS-rebind to localhost:3001 and issue MCP tool calls. The start_debugging tool accepts a fileFullPath that is passed to VS Code's Python launcher; using a \\SERVER\SHARE UNC path, one HTTP request makes the debugger pull and execute attacker-controlled code under the victim's user context.
Mitigation
Upgrade DebugMCP to 1.2.0+ (fix in commit 86776b2); until patched, don't install the extension on hosts with browser access to untrusted sites and do not bind the server beyond 127.0.0.1.