Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2025-66335: SQL injection flaw in Apache Doris MCP Server before 0.6.1

Apache Doris MCP Server versions before 0.6.1 contain an improper neutralization flaw in query context handling that could allow execution of unintended SQL statements and bypass of query validation and access restrictions via the MCP query execution interface. The issue is fixed in version 0.6.1.

Disclosed 17 April 2026 · Record updated 13 September 2026

Impact

Allows execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-66335