{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amysql_mcp_server_projectmysql_mcp_server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mysql_mcp_server_project:mysql_mcp_server:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mysql_mcp_server (\u003c 0.4.2)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","sql-injection","mcp"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe \u003ccode\u003emysql_mcp_server\u003c/code\u003e package (prior to v0.4.2) contains a critical security vulnerability when configured to use the Server-Sent Events (SSE) transport mode. Due to the failure to instantiate \u003ccode\u003eSseServerTransport\u003c/code\u003e with \u003ccode\u003esecurity_settings\u003c/code\u003e, the application lacks essential protections, including DNS-rebinding prevention, CORS middleware, and TrustedHost validation. Furthermore, the application exposes unauthenticated endpoints (\u003ccode\u003e/\u003c/code\u003e, \u003ccode\u003e/sse\u003c/code\u003e, and \u003ccode\u003e/messages/\u003c/code\u003e) and binds to \u003ccode\u003e0.0.0.0\u003c/code\u003e by default.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can exploit this configuration to execute arbitrary SQL commands against the database backend. If the database user is configured with \u003ccode\u003eFILE\u003c/code\u003e privileges, this vulnerability enables arbitrary file read and write operations, which can be leveraged to achieve remote code execution by dropping a malicious web shell. Instances exposed to the internet are at high risk, as are local instances susceptible to browser-based DNS-rebinding attacks. 25 publicly reachable instances have already been identified.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an exposed MySQL MCP Server instance running with \u003ccode\u003eMCP_TRANSPORT=sse\u003c/code\u003e on a public interface (0.0.0.0).\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated HTTP POST request to the \u003ccode\u003e/messages\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes a JSON payload containing a malicious SQL query within the \u003ccode\u003eexecute_sql\u003c/code\u003e tool call.\u003c/li\u003e\n\u003cli\u003eThe server receives the request and, lacking authentication middleware, processes the tool call directly.\u003c/li\u003e\n\u003cli\u003eThe application invokes \u003ccode\u003ecursor.execute(query)\u003c/code\u003e using the attacker-supplied, unsanitized SQL.\u003c/li\u003e\n\u003cli\u003eThe database executes the query, returning results to the attacker or performing file system operations (e.g., \u003ccode\u003eINTO OUTFILE\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker successfully achieves data exfiltration or writes a malicious payload to the host system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full database exfiltration, modification, and potential system compromise. Attackers can leverage MySQL's \u003ccode\u003eFILE\u003c/code\u003e privileges to read sensitive files or write executable files (web shells) to the underlying server. Evidence suggests 25 publicly exposed instances are currently reachable, posing an immediate risk to environments utilizing this server for LLM-integrated database tasks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003emysql_mcp_server\u003c/code\u003e to version 0.4.2 or later immediately to enable mandatory security settings.\u003c/li\u003e\n\u003cli\u003eConfigure the server to bind to \u003ccode\u003e127.0.0.1\u003c/code\u003e rather than \u003ccode\u003e0.0.0.0\u003c/code\u003e if remote access is not required.\u003c/li\u003e\n\u003cli\u003eEnsure the database user assigned to the MCP server follows the principle of least privilege, specifically revoking \u003ccode\u003eFILE\u003c/code\u003e access if not strictly required.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control (firewall or VPN) to restrict access to the SSE transport interface.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-12T00:57:18Z","date_published":"2026-09-12T00:57:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mysql-mcp-server-rce/","summary":"The mysql_mcp_server package (v \u003c 0.4.2) fails to implement security protections in SSE transport mode, enabling unauthenticated attackers to perform arbitrary SQL execution, data exfiltration, and potential remote code execution.","title":"Unauthenticated SQL Execution and RCE in MySQL MCP Server via SSE Transport","url":"https://feed.craftedsignal.io/briefs/2026-09-mysql-mcp-server-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:mysql_mcp_server_project:mysql_mcp_server:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}