Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Cherno.X

#33491of 56,326
8.1Total CVSS
Vulnerabilities · 1
PT-2026-51281
8.1
2026-06-22
Apache · Apache Doris Mcp Server · CVE-2025-66336
**Name of the Vulnerable Software and Affected Versions** Apache Doris MCP Server versions prior to 0.6.1 **Description** A SQL injection exists in a metadata query path where a user-controlled database name is directly interpolated into a SQL query. The query is executed without the caller's authorization context, allowing an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope. **Recommendations** Upgrade to version 0.6.1 or later.