CVE-2026-44969
📛 CVE Title
(no title)
Description
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- low
- CVSS score
- 2.5 / 10
- CVSS vector
AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N- Effective score
- 2.5 / 10 LOW source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-44969
NVD / KEV / EPSS data refreshed 2026-05-25 00:08 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-44993 - Assigner
- GitHub_M
- Published
- Jul 16, 2026, 5:49:50 PM
- Updated
- Jul 17, 2026, 6:06:51 PM
- EUVD base score (CVSS 3.1)
-
2.5 / 10
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N - EUVD-reported EPSS
- 0.1500
- Vendors
- dbt-labs
- Products
-
dbt-mcp (< 1.17.1)
- Aliases
-
GHSA-7xgw-6qf3-7w59,PYSEC-2026-2441
ENISA description: dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when DBT_MCP_SERVER_FILE_LOGGING=true, preserving sensitive sql_query, vars, and node_selection values in plaintext without automatic rotation or deletion. This issue is fixed in version 1.17.1.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (2)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2026-44969 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-44969 tenable:www.cve.org
Remediations (10)
-
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-05-26 03:08 UTC -
web:feedly.com
CVE-2026-44969 Insertion of Sensitive Information into Log File (CWE-532)
2026-05-26 03:08 UTC -
web:forums.ea.com
Broken and Updated Sims 4 Mods and CC: patch 1.124, May 12 and 21, 2026 About This Thread This thread tracks Sims 4 mods and CC that have been "broken" or made obsolete by game update 1.124, May 12, 2026 , and the May 21 hotfix, or declared unsupported by their creators.
2026-05-26 03:08 UTC -
web:github.com
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
2026-05-26 03:08 UTC -
web:guide.sonatype.com
Find vulnerabilities. Fix fast with AI. Search components by package, version, or CVE to get started. Unlock full vulnerability insights and fix guidance with Sonatype Guide.
2026-05-26 03:08 UTC -
web:support.microsoft.com
The Excel file also contains detailed fix lists. Download this Excel file now. Note: Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format.
2026-05-26 03:08 UTC -
web:threatprotect.qualys.com
Zero-day Vulnerabilities Patched in April Patch Tuesday Edition CVE - 2026 -33825: Microsoft Defender Elevation of Privilege Vulnerability Microsoft Defender is a comprehensive, AI-powered security suite that provides malware protection, phishing detection, and web protection for individuals and businesses.
2026-05-26 03:08 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.
2026-05-26 03:08 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-26 03:08 UTC -
web:www.oracle.com
Oracle Critical Patch Update Advisory - April 2026 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...
2026-05-26 03:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.