dbt-mcp is vulnerable to Exposure of Sensitive Information
50
Medium Risk
The local OAuth helper in dbt-mcp exposes dbt Platform access and refresh tokens to other local processes and users. The POST /selected_projects endpoint returns the complete DbtPlatformContext object, including plaintext access and refresh tokens, without authentication or redaction, and the persisted context file at ~/.dbt/mcp.yml is written with overly permissive default permissions readable by other local users. This lets a local process or co-located user obtain credentials that grant offline access to the dbt Platform account. The fix restricts the OAuth context file to owner-only permissions and stops the project-selection endpoint from returning the full token-bearing context payload.
You are affected if you are using a version that falls within the vulnerable range and you use the local dbt Platform OAuth login flow.
dbt-mcp is vulnerable to Exposure of Sensitive Information in versions 1.15.0 - 2.1.1.
Upgrade the dbt-mcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant