<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:55:58.046369+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-33980</id>
    <title>CVE-2026-33980 — Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries</title>
    <updated>2026-10-06T06:55:58.048078+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> pab1it0 adx-mcp-server</p>
<p>Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster. Commit 0abe0ee55279e111281076393e5e966335fffd30 patches the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-33980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vphc-468g-8rfp</id>
    <title>GHSA-vphc-468g-8rfp — Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries</title>
    <updated>2026-10-06T06:55:58.048135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: adx-mcp-server</p>
<p>### Summary</p>
<p>adx-mcp-server (&lt;= latest, commit 48b2933) contains KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster.</p>
<p>### Details</p>
<p>The MCP tools construct KQL queries by directly embedding the `table_name` parameter into query strings:</p>
<p>**Vulnerable code** ([permalink](https://github.com/pab1it0/adx-mcp-server/blob/48b2933/src/adx_mcp_server/server.py#L228)):</p>
<p>```python
@mcp.tool(...)
async def get_table_schema(table_name: str) -&gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f"{table_name} | getschema"          # &lt;-- KQL injection
    result_set = client.execute(config.database, query)
```</p>
<p>```python
@mcp.tool(...)
async def sample_table_data(table_name: str, sample_size: int = 10) -&gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f"{table_name} | sample {sample_size}"  # &lt;-- KQL injection
    result_set = client.execute(config.database, query)
```</p>
<p>```python
@mcp.tool(...)
async def get_table_details(table_name: str) -&gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f".show table {table_name} details"     # &lt;-- KQL injection
    result_set = client.execute(config.database, quer…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vphc-468g-8rfp"/>
  </entry>
</feed>
