CVE-2026-59971: Critical severity pip/mysql-mcp-server vulnerability
Summary
In SSE/HTTP transport mode, mysqlmcpserver constructs SseServerTransport without passing securitysettings. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route.
Trigger condition: MCPTRANSPORT=sse. The default stdio mode is not affected.
Attack Scenarios
Scenario A — Direct exposure: Any network attacker can invoke executesql to run arbitrary SQL without credentials → full data dump, and via MySQL FILE privileges, arbitrary file read/write and RCE.
Scenario B — DNS rebinding (local bind): An attacker lures a victim's browser to a malicious page, rebinds their domain to 127.0.0.1, and uses the browser as a proxy to invoke executesql as same-origin.
Root Cause
In src/mysqlmcpserver/server.py:
1. SseServerTransport is constructed without securitysettings — the SDK defaults enablednsrebindingprotection to False. 2. The Starlette app has no CORS or TrustedHost middleware. 3. All three routes (/, /sse, /messages/) are unauthenticated. 4. The service binds to 0.0.0.0 by default. 5. The sink is cursor.execute(query) with a fully attacker-controlled query.
Impact
- Unauthenticated arbitrary SQL execution against the configured database - Full data exfiltration and modification - If the MySQL account holds FILE privilege: arbitrary file read (LOADFILE) and write (INTO OUTFILE) — potential RCE via webshell drop - Internet-wide scanning has identified 25 publicly reachable SSE instances of this project
Fix
Released in v0.4.2: DNS-rebinding protection is now enabled by passing TransportSecuritySettings(enablednsrebindingprotection=True) to SseServerTransport, and the documented recommended bind address is 127.0.0.1.
Credits
Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/mysql-mcp-serverto a version that resolves this vulnerability.Fixed in 0.4.2 - Upgrade
Upgrade
MCP Python SDKto a version that resolves this vulnerability.Fixed in 0.4.2 - Configuration
In SSE/HTTP transport mode, construct `SseServerTransport` with `TransportSecuritySettings(enable_dns_rebinding_protection=True)` (fixed/enabled in v0.4.2).
SseServerTransport (MCP Python SDK) enable_dns_rebinding_protection = True - Configuration
Set the service bind address to the documented recommended value `127.0.0.1` instead of the default `0.0.0.0` to prevent direct exposure and local bind scenarios.
Starlette/MySQL MCP service bind address bind = 127.0.0.1
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using SSE/HTTP transport are exposed when MCP_TRANSPORT=sse. The default stdio mode is not affected; SSE/HTTP binds to 0.0.0.0 by default and exposes routes without authentication.
What does an attacker need to exploit the issue?
For a directly reachable SSE/HTTP service, an attacker needs only network access and no credentials or user interaction. For a service bound locally, an attacker can use DNS rebinding by convincing a victim to visit a malicious page and then proxy requests through the victim's browser.
What impact can successful exploitation have?
An attacker can invoke execute_sql to run arbitrary SQL, including dumping database contents. Where the MySQL account has FILE privileges, this can also permit arbitrary file reads or writes and potentially remote code execution.
How can I determine whether my deployment is affected?
Check whether MCP_TRANSPORT is set to sse and whether the service is reachable over HTTP. The affected configuration has unauthenticated routes at /, /sse, and /messages/ and lacks the SDK DNS-rebinding security settings.