PT-2026-29682 · Unknown · Mcp-Data-Vis

Bigw

+1

·

Published

2026-04-02

·

Updated

2026-04-27

·

CVE-2026-5322

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AlejandroArciniegas mcp-data-vis (affected versions not specified)
Description A SQL injection issue exists in the Request function within the src/servers/database/server.js file of the MCP Handler component. This manipulation can be initiated remotely. The exploit has been publicly disclosed. The product uses a rolling release model, so specific version information is unavailable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5322

Affected Products

Mcp-Data-Vis