s1
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-44969

📛 CVE Title

(no title)

Description

dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

Overview

State
—
Assigner (CNA)
—
CVSS severity
low
CVSS score
CVSS 2.5 / 10 2.5 2.5 / 10
CVSS vector
AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Effective score
2.5 / 10 LOW source: CNA overview
CWE(s)
—
Reserved
—
Published
—
Last updated
—
Source
https://www.tenable.com/cve/CVE-2026-44969

NVD / KEV / EPSS data refreshed 2026-05-25 00:08 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-44993
Assigner
GitHub_M
Published
Jul 16, 2026, 5:49:50 PM
Updated
Jul 17, 2026, 6:06:51 PM
EUVD base score (CVSS 3.1)
2.5 / 10
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EUVD-reported EPSS
0.1500
Vendors
dbt-labs
Products
dbt-mcp (< 1.17.1)
Aliases
GHSA-7xgw-6qf3-7w59, PYSEC-2026-2441

ENISA description: dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote those records to dbt-mcp.log when DBT_MCP_SERVER_FILE_LOGGING=true, preserving sensitive sql_query, vars, and node_selection values in plaintext without automatic rotation or deletion. This issue is fixed in version 1.17.1.

EUVD references (4)

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

Web references (2)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Remediations (10)

  • web:epatch.pa.gov

    Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...

    2026-05-26 03:08 UTC
  • web:feedly.com

    CVE-2026-44969 Insertion of Sensitive Information into Log File (CWE-532)

    2026-05-26 03:08 UTC
  • web:forums.ea.com

    Broken and Updated Sims 4 Mods and CC: patch 1.124, May 12 and 21, 2026 About This Thread This thread tracks Sims 4 mods and CC that have been "broken" or made obsolete by game update 1.124, May 12, 2026 , and the May 21 hotfix, or declared unsupported by their creators.

    2026-05-26 03:08 UTC
  • web:github.com

    dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

    2026-05-26 03:08 UTC
  • web:guide.sonatype.com

    Find vulnerabilities. Fix fast with AI. Search components by package, version, or CVE to get started. Unlock full vulnerability insights and fix guidance with Sonatype Guide.

    2026-05-26 03:08 UTC
  • web:support.microsoft.com

    The Excel file also contains detailed fix lists. Download this Excel file now. Note: Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format.

    2026-05-26 03:08 UTC
  • web:threatprotect.qualys.com

    Zero-day Vulnerabilities Patched in April Patch Tuesday Edition CVE - 2026 -33825: Microsoft Defender Elevation of Privilege Vulnerability Microsoft Defender is a comprehensive, AI-powered security suite that provides malware protection, phishing detection, and web protection for individuals and businesses.

    2026-05-26 03:08 UTC
  • web:www.bleepingcomputer.com

    Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.

    2026-05-26 03:08 UTC
  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

    2026-05-26 03:08 UTC
  • web:www.oracle.com

    Oracle Critical Patch Update Advisory - April 2026 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...

    2026-05-26 03:08 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-44969.json.

Not stored.