PT-2026-90533 · Pypi · Mysql-Mcp-Server

CVE-2026-59971

·

Published

2026-09-11

·

Updated

2026-09-11

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Summary

In SSE/HTTP transport mode, mysql mcp server constructs SseServerTransport without passing security settings. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route.
Trigger condition: MCP TRANSPORT=sse. The default stdio mode is not affected.

Attack Scenarios

Scenario A — Direct exposure: Any network attacker can invoke execute sql to run arbitrary SQL without credentials → full data dump, and via MySQL FILE privileges, arbitrary file read/write and RCE.
Scenario B — DNS rebinding (local bind): An attacker lures a victim's browser to a malicious page, rebinds their domain to 127.0.0.1, and uses the browser as a proxy to invoke execute sql as same-origin.

Root Cause

In src/mysql mcp server/server.py:
  1. SseServerTransport is constructed without security settings — the SDK defaults enable dns rebinding protection to False.
  2. The Starlette app has no CORS or TrustedHost middleware.
  3. All three routes (/, /sse, /messages/) are unauthenticated.
  4. The service binds to 0.0.0.0 by default.
  5. The sink is cursor.execute(query) with a fully attacker-controlled query.

Impact

  • Unauthenticated arbitrary SQL execution against the configured database
  • Full data exfiltration and modification
  • If the MySQL account holds FILE privilege: arbitrary file read (LOAD FILE) and write (INTO OUTFILE) — potential RCE via webshell drop
  • Internet-wide scanning has identified 25 publicly reachable SSE instances of this project

Fix

Released in v0.4.2: DNS-rebinding protection is now enabled by passing TransportSecuritySettings(enable dns rebinding protection=True) to SseServerTransport, and the documented recommended bind address is 127.0.0.1.

Credits

Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).

Fix

Origin Validation Error

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59971
GHSA-RQFV-2MW9-78G2

Affected Products

Mysql-Mcp-Server