PT-2026-51281 · Apache · Apache Doris Mcp Server

·

CVE-2025-66336

·

Published

2026-06-22

·

Updated

2026-06-26

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Doris MCP Server versions prior to 0.6.1
Description A SQL injection exists in a metadata query path where a user-controlled database name is directly interpolated into a SQL query. The query is executed without the caller's authorization context, allowing an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.
Recommendations Upgrade to version 0.6.1 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66336
GHSA-PQRJ-4GWG-H5F7

Affected Products

Apache Doris Mcp Server