SQL Injection Affecting mysql-mcp-server package, versions [,0.3.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
Exploit Maturity
Proof of Concept
EPSS
0.21% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-MYSQLMCPSERVER-17326848
  • published12 Jun 2026
  • disclosed8 Jun 2026
  • creditBlackBird_BB

Introduced: 8 Jun 2026

CVE-2026-11529  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade mysql-mcp-server to version 0.3.0 or higher.

Overview

mysql-mcp-server is an A Model Context Protocol (MCP) server that enables secure interaction with MySQL databases. This server allows AI assistants to list tables, read data, and execute SQL queries through a controlled interface, making database exploration and analysis safer and more structured.

Affected versions of this package are vulnerable to SQL Injection via the read_resource() function in the mysql URI Handler. An attacker can execute unauthorized SQL commands by supplying crafted input to the uri_str argument.

CVSS Base Scores

version 4.0
version 3.1