MCPwned weaponizes a widely overlooked MCP-spec weakness, browser-based DNS rebinding, against SSE & streaming-HTTP MCP servers to exfiltrate data and escalate access. This skeleton key vulnerability hacks your locally running MCP server, just by getting you to visit a malicious website.