<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:56:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277926</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277926</link>
      <description>EUVD-2026-277926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277926</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33980</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33980</link>
      <description>&lt;p&gt;Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster. Commit 0abe0ee55279e111281076393e5e966335fffd30 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster. Commit 0abe0ee55279e111281076393e5e966335fffd30 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33980</guid>
    </item>
    <item>
      <title>GHSA-vphc-468g-8rfp — Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vphc-468g-8rfp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: adx-mcp-server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;adx-mcp-server (&amp;lt;= latest, commit 48b2933) contains KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The MCP tools construct KQL queries by directly embedding the `table_name` parameter into query strings:&lt;/p&gt;
&lt;p&gt;**Vulnerable code** ([permalink](https://github.com/pab1it0/adx-mcp-server/blob/48b2933/src/adx_mcp_server/server.py#L228)):&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def get_table_schema(table_name: str) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;{table_name} | getschema&amp;#34;          # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, query)
```&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def sample_table_data(table_name: str, sample_size: int = 10) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;{table_name} | sample {sample_size}&amp;#34;  # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, query)
```&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def get_table_details(table_name: str) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;.show table {table_name} details&amp;#34;     # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, quer…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: adx-mcp-server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;adx-mcp-server (&amp;lt;= latest, commit 48b2933) contains KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The MCP tools construct KQL queries by directly embedding the `table_name` parameter into query strings:&lt;/p&gt;
&lt;p&gt;**Vulnerable code** ([permalink](https://github.com/pab1it0/adx-mcp-server/blob/48b2933/src/adx_mcp_server/server.py#L228)):&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def get_table_schema(table_name: str) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;{table_name} | getschema&amp;#34;          # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, query)
```&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def sample_table_data(table_name: str, sample_size: int = 10) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;{table_name} | sample {sample_size}&amp;#34;  # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, query)
```&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def get_table_details(table_name: str) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;.show table {table_name} details&amp;#34;     # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, quer…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vphc-468g-8rfp</guid>
    </item>
    <item>
      <title>PYSEC-2026-2327 — Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2327</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: adx-mcp-server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;adx-mcp-server (&amp;lt;= latest, commit 48b2933) contains KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The MCP tools construct KQL queries by directly embedding the `table_name` parameter into query strings:&lt;/p&gt;
&lt;p&gt;**Vulnerable code** ([permalink](https://github.com/pab1it0/adx-mcp-server/blob/48b2933/src/adx_mcp_server/server.py#L228)):&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def get_table_schema(table_name: str) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;{table_name} | getschema&amp;#34;          # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, query)
```&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def sample_table_data(table_name: str, sample_size: int = 10) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;{table_name} | sample {sample_size}&amp;#34;  # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, query)
```&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def get_table_details(table_name: str) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;.show table {table_name} details&amp;#34;     # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, quer…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: adx-mcp-server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;adx-mcp-server (&amp;lt;= latest, commit 48b2933) contains KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The MCP tools construct KQL queries by directly embedding the `table_name` parameter into query strings:&lt;/p&gt;
&lt;p&gt;**Vulnerable code** ([permalink](https://github.com/pab1it0/adx-mcp-server/blob/48b2933/src/adx_mcp_server/server.py#L228)):&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def get_table_schema(table_name: str) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;{table_name} | getschema&amp;#34;          # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, query)
```&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def sample_table_data(table_name: str, sample_size: int = 10) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;{table_name} | sample {sample_size}&amp;#34;  # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, query)
```&lt;/p&gt;
&lt;p&gt;```python
@mcp.tool(...)
async def get_table_details(table_name: str) -&amp;gt; List[Dict[str, Any]]:
    client = get_kusto_client()
    query = f&amp;#34;.show table {table_name} details&amp;#34;     # &amp;lt;-- KQL injection
    result_set = client.execute(config.database, quer…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2327</guid>
    </item>
  </channel>
</rss>
