PT-2026-47311 · Designcomputer+1 · Mysql-Mcp-Server
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
designcomputer mysql-mcp-server versions prior to 0.3.0
Description
An issue exists in the mysql URI Handler component within the
read resource() function of the src/mysql mcp server/server.py file. Manipulation of the uri str argument allows for remote SQL injection, which occurs when an attacker can interfere with the queries that an application makes to its database.Recommendations
Update to version 0.3.0.
As a temporary mitigation, restrict access to the
read resource() function.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mysql-Mcp-Server