oss-sec mailing list archives
CVE-2025-66335: Apache Doris MCP Server: MCP SQL inject
From: Mingyu Chen <morningman () apache org>
Date: Fri, 17 Apr 2026 09:34:31 +0000
Severity: moderate Affected versions: - Apache Doris MCP Server 0.1.0 before 0.6.1 Description: Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected. Credit: Tomer Peled, Senior Security Researcher at Akamai (reporter) References: https://doris.apache.org https://www.cve.org/CVERecord?id=CVE-2025-66335
Current thread:
- CVE-2025-66335: Apache Doris MCP Server: MCP SQL inject Mingyu Chen (Apr 17)
