Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
659525
AlmaLinux
4796
Alpaquita
9617
Alpine
4141
Android
3262
Azure Linux
12016
BellSoft Hardened Containers
467
Bitnami
7872
Chainguard
6385
CleanStart
1122
CRAN
14
crates.io
2403
Debian
56228
Echo
4067
GHC
3
GIT
81570
GitHub Actions
52
Go
6960
Hackage
31
Hex
101
Julia
845
Linux
15361
Mageia
5922
Maven
6488
MinimOS
41448
npm
218747
NuGet
1707
opam
14
openEuler
6841
openSUSE
12811
OSS-Fuzz
3884
Packagist
6286
Pub
11
PyPI
19661
Red Hat
20130
Rocky Linux
3135
Root
14085
RubyGems
1963
SUSE
20561
SwiftURL
51
Ubuntu
54349
VSCode
18
Wolfi
4100
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-jj54-r8gm-2fcf
PyPI/dbt-mcp
dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
14 May
Fix available
Severity - 3.1 (Low)
GHSA-7xgw-6qf3-7w59
PyPI/dbt-mcp
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
14 May
Fix available
Severity - 2.5 (Low)
GHSA-xpww-f6pm-cfhq
PyPI/dbt-mcp
dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
14 May
Fix available
Severity - 6.3 (Medium)
PyPI - OSV