PT-2026-36536 · Unknown · Astro-Mcp-Server

Eternity

·

Published

2026-05-01

·

Updated

2026-05-02

·

CVE-2026-7591

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions astro-mcp-server versions prior to 1.1.2
Description A flaw in the MCP Tool Query Construction component, specifically within a function in the src/index.ts file, allows for remote SQL injection. This occurs when the request.params.arguments argument is manipulated. SQL injection is a technique where an attacker inserts malicious SQL code into a query, potentially allowing them to view, modify, or delete data from the database.
Recommendations Update to version 1.1.2 or later. As a temporary workaround, restrict or validate the input passed to the request.params.arguments argument to prevent malicious SQL code execution.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7591

Affected Products

Astro-Mcp-Server