CVE-2025-66335: SQL injection flaw in Apache Doris MCP Server before 0.6.1
Apache Doris MCP Server versions before 0.6.1 contain an improper neutralization flaw in query context handling that could allow execution of unintended SQL statements and bypass of query validation and access restrictions via the MCP query execution interface. The issue is fixed in version 0.6.1.
Disclosed 17 April 2026 · Record updated 13 September 2026
Impact
Allows execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-66335
