CVE-2025-66335: Apache Doris MCP Server: MCP SQL inject
Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Doris MCP Serverto a version that resolves this vulnerability.Fixed in 0.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66335?
CVE-2025-66335 is considered a critical vulnerability due to its potential for SQL injection.
How do I fix CVE-2025-66335?
To fix CVE-2025-66335, upgrade to Apache Doris MCP Server version 0.6.1 or later.
What systems are affected by CVE-2025-66335?
CVE-2025-66335 affects Apache Doris MCP Server versions earlier than 0.6.1.
What type of vulnerability is CVE-2025-66335?
CVE-2025-66335 is an improper neutralization flaw that can lead to SQL injection.
Can CVE-2025-66335 lead to unauthorized access?
Yes, CVE-2025-66335 can allow attackers to bypass intended query validation and access restrictions.