<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:07:02 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-59971 — MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding…</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-59971</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; designcomputer mysql_mcp_server&lt;/p&gt;
&lt;p&gt;MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection, while the Starlette routes /, /sse, and /messages/ have no authentication and the service binds to 0.0.0.0 by default. A network attacker can directly reach execute_sql, or can use DNS rebinding to make a victim&amp;#39;s browser relay same-origin requests to a locally bound service, and supply a query that reaches cursor.execute(query). This allows unauthenticated disclosure and modification of the configured database; when the MySQL account has FILE privileges, the same access can read or write server files and may enable code execution. The default stdio transport is not affected. This issue is fixed in 0.4.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; designcomputer mysql_mcp_server&lt;/p&gt;
&lt;p&gt;MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection, while the Starlette routes /, /sse, and /messages/ have no authentication and the service binds to 0.0.0.0 by default. A network attacker can directly reach execute_sql, or can use DNS rebinding to make a victim&amp;#39;s browser relay same-origin requests to a locally bound service, and supply a query that reaches cursor.execute(query). This allows unauthenticated disclosure and modification of the configured database; when the MySQL account has FILE privileges, the same access can read or write server files and may enable code execution. The default stdio transport is not affected. This issue is fixed in 0.4.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-59971</guid>
    </item>
    <item>
      <title>GHSA-rqfv-2mw9-78g2 — MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rqfv-2mw9-78g2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mysql-mcp-server&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK&amp;#39;s DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route.&lt;/p&gt;
&lt;p&gt;**Trigger condition:** `MCP_TRANSPORT=sse`. The default stdio mode is not affected.&lt;/p&gt;
&lt;p&gt;## Attack Scenarios&lt;/p&gt;
&lt;p&gt;**Scenario A — Direct exposure:** Any network attacker can invoke `execute_sql` to run arbitrary SQL without credentials → full data dump, and via MySQL `FILE` privileges, arbitrary file read/write and RCE.&lt;/p&gt;
&lt;p&gt;**Scenario B — DNS rebinding (local bind):** An attacker lures a victim&amp;#39;s browser to a malicious page, rebinds their domain to `127.0.0.1`, and uses the browser as a proxy to invoke `execute_sql` as same-origin.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;In `src/mysql_mcp_server/server.py`:&lt;/p&gt;
&lt;p&gt;1. `SseServerTransport` is constructed without `security_settings` — the SDK defaults `enable_dns_rebinding_protection` to `False`.
2. The Starlette app has no CORS or TrustedHost middleware.
3. All three routes (`/`, `/sse`, `/messages/`) are unauthenticated.
4. The service binds to `0.0.0.0` by default.
5. The sink is `cursor.execute(query)` with a fully attacker-controlled query.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- Unauthenticated arbitrary SQL execution against the configured database
- Full data exfiltration and modification
- If the MySQL account h…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mysql-mcp-server&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK&amp;#39;s DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route.&lt;/p&gt;
&lt;p&gt;**Trigger condition:** `MCP_TRANSPORT=sse`. The default stdio mode is not affected.&lt;/p&gt;
&lt;p&gt;## Attack Scenarios&lt;/p&gt;
&lt;p&gt;**Scenario A — Direct exposure:** Any network attacker can invoke `execute_sql` to run arbitrary SQL without credentials → full data dump, and via MySQL `FILE` privileges, arbitrary file read/write and RCE.&lt;/p&gt;
&lt;p&gt;**Scenario B — DNS rebinding (local bind):** An attacker lures a victim&amp;#39;s browser to a malicious page, rebinds their domain to `127.0.0.1`, and uses the browser as a proxy to invoke `execute_sql` as same-origin.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;In `src/mysql_mcp_server/server.py`:&lt;/p&gt;
&lt;p&gt;1. `SseServerTransport` is constructed without `security_settings` — the SDK defaults `enable_dns_rebinding_protection` to `False`.
2. The Starlette app has no CORS or TrustedHost middleware.
3. All three routes (`/`, `/sse`, `/messages/`) are unauthenticated.
4. The service binds to `0.0.0.0` by default.
5. The sink is `cursor.execute(query)` with a fully attacker-controlled query.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;- Unauthenticated arbitrary SQL execution against the configured database
- Full data exfiltration and modification
- If the MySQL account h…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rqfv-2mw9-78g2</guid>
    </item>
  </channel>
</rss>
