CVE-2025-66336: Apache Doris MCP Server: SQL injection leading the authentication bypass
Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.
Affected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Doris (MCP Server)to a version that resolves this vulnerability.Fixed in 0.6.1Patch CVE-2025-66336
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66336?
CVE-2025-66336 has a risk rating of 30, indicating its high severity due to the potential for SQL injection and authentication bypass.
How do I fix CVE-2025-66336?
To fix CVE-2025-66336, ensure that user-controlled inputs are properly sanitized and never directly interpolated into SQL queries.
What kind of vulnerability is CVE-2025-66336?
CVE-2025-66336 is a SQL injection vulnerability that can lead to an authentication bypass in Apache Doris MCP Server.
Who is affected by CVE-2025-66336?
CVE-2025-66336 affects users of the Apache Doris MCP Server who rely on the compromised metadata query path.
Can CVE-2025-66336 be exploited by unauthenticated users?
Yes, CVE-2025-66336 can potentially be exploited by both authenticated attackers and anonymous users.