oss-sec mailing list archives

CVE-2025-66335: Apache Doris MCP Server: MCP SQL inject


From: Mingyu Chen <morningman () apache org>
Date: Fri, 17 Apr 2026 09:34:31 +0000

Severity: moderate 

Affected versions:

- Apache Doris MCP Server 0.1.0 before 0.6.1

Description:

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context 
handling that may allow execution of unintended SQL statements and bypass of intended query validation and access 
restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.

Credit:

Tomer Peled, Senior Security Researcher at Akamai (reporter)

References:

https://doris.apache.org
https://www.cve.org/CVERecord?id=CVE-2025-66335


Current thread: