CVE-2026-59971: Critical severity pip/mysql-mcp-server vulnerability

Published Sep 11, 2026
·
Updated

Summary

In SSE/HTTP transport mode, mysqlmcpserver constructs SseServerTransport without passing securitysettings. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route.

Trigger condition: MCPTRANSPORT=sse. The default stdio mode is not affected.

Attack Scenarios

Scenario A — Direct exposure: Any network attacker can invoke executesql to run arbitrary SQL without credentials → full data dump, and via MySQL FILE privileges, arbitrary file read/write and RCE.

Scenario B — DNS rebinding (local bind): An attacker lures a victim's browser to a malicious page, rebinds their domain to 127.0.0.1, and uses the browser as a proxy to invoke executesql as same-origin.

Root Cause

In src/mysqlmcpserver/server.py:

1. SseServerTransport is constructed without securitysettings — the SDK defaults enablednsrebindingprotection to False. 2. The Starlette app has no CORS or TrustedHost middleware. 3. All three routes (/, /sse, /messages/) are unauthenticated. 4. The service binds to 0.0.0.0 by default. 5. The sink is cursor.execute(query) with a fully attacker-controlled query.

Impact

- Unauthenticated arbitrary SQL execution against the configured database - Full data exfiltration and modification - If the MySQL account holds FILE privilege: arbitrary file read (LOADFILE) and write (INTO OUTFILE) — potential RCE via webshell drop - Internet-wide scanning has identified 25 publicly reachable SSE instances of this project

Fix

Released in v0.4.2: DNS-rebinding protection is now enabled by passing TransportSecuritySettings(enablednsrebindingprotection=True) to SseServerTransport, and the documented recommended bind address is 127.0.0.1.

Credits

Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).

Affected Software

1 affected componentFixes available
pip/mysql-mcp-server<0.4.2
0.4.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/mysql-mcp-server to a version that resolves this vulnerability.

    Fixed in 0.4.2
  2. Upgrade

    Upgrade MCP Python SDK to a version that resolves this vulnerability.

    Fixed in 0.4.2
  3. Configuration

    In SSE/HTTP transport mode, construct `SseServerTransport` with `TransportSecuritySettings(enable_dns_rebinding_protection=True)` (fixed/enabled in v0.4.2).

    SseServerTransport (MCP Python SDK) enable_dns_rebinding_protection = True
  4. Configuration

    Set the service bind address to the documented recommended value `127.0.0.1` instead of the default `0.0.0.0` to prevent direct exposure and local bind scenarios.

    Starlette/MySQL MCP service bind address bind = 127.0.0.1

Event History

Sep 11, 2026
Advisory Published
via GitHub·08:35 PM
Data Sourced
via GitHub·08:35 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using SSE/HTTP transport are exposed when MCP_TRANSPORT=sse. The default stdio mode is not affected; SSE/HTTP binds to 0.0.0.0 by default and exposes routes without authentication.

2

What does an attacker need to exploit the issue?

For a directly reachable SSE/HTTP service, an attacker needs only network access and no credentials or user interaction. For a service bound locally, an attacker can use DNS rebinding by convincing a victim to visit a malicious page and then proxy requests through the victim's browser.

3

What impact can successful exploitation have?

An attacker can invoke execute_sql to run arbitrary SQL, including dumping database contents. Where the MySQL account has FILE privileges, this can also permit arbitrary file reads or writes and potentially remote code execution.

4

How can I determine whether my deployment is affected?

Check whether MCP_TRANSPORT is set to sse and whether the service is reachable over HTTP. The affected configuration has unauthenticated routes at /, /sse, and /messages/ and lacks the SDK DNS-rebinding security settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203