CVE-2026-85788: Incomplete list of disallowed inputs in awslabs mysql-mcp-server

Published Sep 9, 2026
·
Updated

Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace.

To remediate this issue, users should upgrade to version 1.0.23.

Affected Software

1 affected component
awslabs/mysql-mcp-server<=1.0.22

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade awslabs mysql-mcp-server to a version that resolves this vulnerability.

    Fixed in 1.0.23

Event History

Sep 9, 2026
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access and interaction are required to exploit this issue?

The vulnerability is locally exploitable without prior privileges, but it requires user interaction. Exploitation relies on SQL inline comments that the mutable SQL detector's regex engine does not recognize as whitespace.

2

What security boundary can be bypassed?

An attacker may bypass the read-only enforcement gate in the mutable SQL detector. This can allow access to SQL file-read and file-write sinks.

3

Which version addresses the issue?

Upgrade awslabs/mysql-mcp-server to version 1.0.23.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203