CVE-2026-48774: ProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read-only contract
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP runsqlreadonly tool violates its documented read-only contract for MySQL targets. The tool validates only the full input string with a substring blacklist and first-keyword allowlist, but then executes the entire SQL string on a backend connection created with CLIENTMULTISTATEMENTS. As a result, a caller can submit a read-only first statement followed by a side-effecting second statement, such as SELECT 1; RENAME TABLE .... The validator accepts the payload because it starts with SELECT and because side-effecting MySQL statements such as RENAME TABLE, SET, RESET, LOCK TABLES, and KILL are not rejected by the blacklist. In a live MCP runtime test, the /mcp/query endpoint accepted a runsqlreadonly request. The MCP response reported success for the first SELECT, and direct backend verification showed that the table had actually been renamed. This violates the endpoint's read-only security contract and lets an MCP caller perform backend writes or administrative SQL, limited by the configured MCP target account's database privileges. Version 3.0.9 contains a fix. Other operator mitigations include: keeping MCP disabled unless required; setting a non-empty mcp-queryendpointauth token before exposing /mcp/query; restricting MCP listener network exposure; configuring MCP backend target credentials as database-level read-only users; and adding temporary MCP query rules to block obvious multi-statement patterns.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ProxySQLto a version that resolves this vulnerability.Fixed in 3.0.9 - Configuration
Keep MCP disabled unless required (disable MCP when not needed)
ProxySQL MCP MCP = disabled - Configuration
Set a non-empty mcp-query_endpoint_auth token before exposing the /mcp/query endpoint
ProxySQL MCP mcp-query_endpoint_auth = non-empty - Configuration
Configure MCP backend target credentials as database-level read-only users
MCP backend target credentials database privileges = read-only - Configuration
Add temporary MCP query rules to block obvious multi-statement SQL patterns to prevent execution of side-effecting multi-statements
ProxySQL MCP query rules query_rules = block multi-statement patterns (temporary) - Compensating control
Restrict MCP listener network exposure (limit access to trusted/internal IPs and networks)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48774?
CVE-2026-48774 has a high severity rating of 7.5.
How do I fix CVE-2026-48774?
To fix CVE-2026-48774, update ProxySQL to version 3.0.9 or later.
What are the risks associated with CVE-2026-48774?
CVE-2026-48774 may allow unintended side-effecting MySQL multi-statements to execute despite a read-only contract.
Which versions of ProxySQL are affected by CVE-2026-48774?
ProxySQL versions 3.0.0 through 3.0.8 are affected by CVE-2026-48774.
What happens if CVE-2026-48774 is exploited?
If exploited, CVE-2026-48774 can result in unauthorized modifications to the database due to the violation of the read-only contract.