PT-2026-36536 · Unknown · Astro-Mcp-Server
Eternity
·
Published
2026-05-01
·
Updated
2026-05-02
·
CVE-2026-7591
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
astro-mcp-server versions prior to 1.1.2
Description
A flaw in the MCP Tool Query Construction component, specifically within a function in the
src/index.ts file, allows for remote SQL injection. This occurs when the request.params.arguments argument is manipulated. SQL injection is a technique where an attacker inserts malicious SQL code into a query, potentially allowing them to view, modify, or delete data from the database.Recommendations
Update to version 1.1.2 or later.
As a temporary workaround, restrict or validate the input passed to the
request.params.arguments argument to prevent malicious SQL code execution.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astro-Mcp-Server