PT-2025-37049 · Mariadb · Mariadb Mcp

·

CVE-2025-56404

·

Published

2025-09-10

·

Updated

2025-09-17

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: MariaDB MCP version 0.1.0
Description: An issue was discovered in the MariaDB MCP software where attackers can gain sensitive information via the SSE service due to a lack of user validation within the service.
Recommendations: Ensure proper user validation is implemented within the SSE service to prevent unauthorized access to sensitive information.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16375
CVE-2025-56404

Affected Products

Mariadb Mcp