CVE-2025-66335

MEDIUM

Apache Doris MCP Server: MCP SQL inject

Title source: cna
STIX 2.1

Description

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 29.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (3)
apache/doris_mcp_server 0.1.0 - 0.6.1
Apache Software Foundation/Apache Doris MCP Server 0.1.0 - 0.6.1
pypi/doris-mcp-server 0.1.0 - 0.6.1PyPI
Published Apr 20, 2026
Tracked Since Apr 20, 2026