PT-2026-56006 · Amazon · Mcp Gateway & Registry
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Amazon mcp-gateway-registry versions prior to 1.0.13
Description
The metrics-service retention policy management component fails to properly neutralize special elements. This allows an authenticated remote user to execute arbitrary SQL queries by providing a crafted
table name value, which is then interpolated into SQL statements in an identifier position.Recommendations
Upgrade to version 1.0.13 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcp Gateway & Registry