GHSA-rqfv-2mw9-78g2

Suggest an improvement
Source
https://github.com/advisories/GHSA-rqfv-2mw9-78g2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rqfv-2mw9-78g2/GHSA-rqfv-2mw9-78g2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rqfv-2mw9-78g2
Aliases
  • CVE-2026-59971
Published
2026-09-11T20:35:42Z
Modified
2026-09-11T20:45:04Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
Details

Summary

In SSE/HTTP transport mode, mysql_mcp_server constructs SseServerTransport without passing security_settings. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route.

Trigger condition: MCP_TRANSPORT=sse. The default stdio mode is not affected.

Attack Scenarios

Scenario A — Direct exposure: Any network attacker can invoke execute_sql to run arbitrary SQL without credentials → full data dump, and via MySQL FILE privileges, arbitrary file read/write and RCE.

Scenario B — DNS rebinding (local bind): An attacker lures a victim's browser to a malicious page, rebinds their domain to 127.0.0.1, and uses the browser as a proxy to invoke execute_sql as same-origin.

Root Cause

In src/mysql_mcp_server/server.py:

  1. SseServerTransport is constructed without security_settings — the SDK defaults enable_dns_rebinding_protection to False.
  2. The Starlette app has no CORS or TrustedHost middleware.
  3. All three routes (/, /sse, /messages/) are unauthenticated.
  4. The service binds to 0.0.0.0 by default.
  5. The sink is cursor.execute(query) with a fully attacker-controlled query.

Impact

  • Unauthenticated arbitrary SQL execution against the configured database
  • Full data exfiltration and modification
  • If the MySQL account holds FILE privilege: arbitrary file read (LOAD_FILE) and write (INTO OUTFILE) — potential RCE via webshell drop
  • Internet-wide scanning has identified 25 publicly reachable SSE instances of this project

Fix

Released in v0.4.2: DNS-rebinding protection is now enabled by passing TransportSecuritySettings(enable_dns_rebinding_protection=True) to SseServerTransport, and the documented recommended bind address is 127.0.0.1.

Credits

Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).

Database specific
{
    "cwe_ids": [
        "CWE-306",
        "CWE-346"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-11T20:35:42Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

PyPI / mysql-mcp-server

Package

Name
mysql-mcp-server
View open source insights on deps.dev
Purl
pkg:pypi/mysql-mcp-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.2

Affected versions

0.*
0.1.0
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rqfv-2mw9-78g2/GHSA-rqfv-2mw9-78g2.json"