PT-2026-90533 · Pypi · Mysql-Mcp-Server
CVE-2026-59971
·
Publicado
2026-09-11
·
Atualizado
2026-09-11
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Summary
In SSE/HTTP transport mode,
mysql mcp server constructs SseServerTransport without passing security settings. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route.Trigger condition:
MCP TRANSPORT=sse. The default stdio mode is not affected.Attack Scenarios
Scenario A — Direct exposure: Any network attacker can invoke
execute sql to run arbitrary SQL without credentials → full data dump, and via MySQL FILE privileges, arbitrary file read/write and RCE.Scenario B — DNS rebinding (local bind): An attacker lures a victim's browser to a malicious page, rebinds their domain to
127.0.0.1, and uses the browser as a proxy to invoke execute sql as same-origin.Root Cause
In
src/mysql mcp server/server.py:SseServerTransportis constructed withoutsecurity settings— the SDK defaultsenable dns rebinding protectiontoFalse.- The Starlette app has no CORS or TrustedHost middleware.
- All three routes (
/,/sse,/messages/) are unauthenticated. - The service binds to
0.0.0.0by default. - The sink is
cursor.execute(query)with a fully attacker-controlled query.
Impact
- Unauthenticated arbitrary SQL execution against the configured database
- Full data exfiltration and modification
- If the MySQL account holds
FILEprivilege: arbitrary file read (LOAD FILE) and write (INTO OUTFILE) — potential RCE via webshell drop - Internet-wide scanning has identified 25 publicly reachable SSE instances of this project
Fix
Released in v0.4.2: DNS-rebinding protection is now enabled by passing
TransportSecuritySettings(enable dns rebinding protection=True) to SseServerTransport, and the documented recommended bind address is 127.0.0.1.Credits
Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).
Correção
Missing Authentication
Origin Validation Error
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mysql-Mcp-Server