Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-34200 — Proof-of-concept demonstrating unauthenticated cross-origin takeover of Nhost MCP Server, enabling database exfiltration, table drops, and permission rewriting. | Kitploit
Tools/GitHubGitHub/skoveit/cve-2026-34200
Vulnerability AnalysisExploitationWeb SecurityPapers & ResearchLearning & Education
GitHubskoveit/cve-2026-34200

CVE-2026-34200

Proof-of-concept demonstrating unauthenticated cross-origin takeover of Nhost MCP Server, enabling database exfiltration, table drops, and permission rewriting.

View Repository
45 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Nhost MCP Server: One-Click Infrastructure Compromise

Official Advisory: This vulnerability was acknowledged and published by Nhost: GHSA-6c5x-3h35-vvw2

This repository documents a vulnerability in the Nhost Local MCP Server. The service lacks inbound authentication and implements a permissive CORS policy, allowing for unauthenticated, cross-origin request execution.

A single visit to an attacker-controlled origin while nhost mcp is active results in a full project takeover. Upon successful execution, an attacker gains unauthorized access to:

  • Exfiltrate production database contents
  • Drop tables via raw SQL migrations
  • Rewrite Hasura permissions
  • Hijack your cloud PAT and Admin Secret

See REPORT.md for the full technical breakdown, root cause analysis, PoC code, and remediation recommendations.

Credits

Discovered and reported by Skove (Anas) — [GitHub].

Coordinated disclosure with the Nhost security team.

Disclaimer: Published for educational and responsible disclosure purposes only. Do not use against systems you don't own.

Download Tool