CVE-2025-56404
HIGHMariadb Model Context Protocol - Improper Input Validation
Title source: ruleDescription
An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.
Scores
CVSS v3
7.5
EPSS
0.0009
EPSS Percentile
25.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-20
Status
published
Affected Products (1)
mariadb/model_context_protocol
Timeline
Published
Sep 10, 2025
Tracked Since
Feb 18, 2026