GHSA-rqfv-2mw9-78g2: Critical severity pip/mysql-mcp-server vulnerability

Published Sep 11, 2026
·
Updated

Summary

In SSE/HTTP transport mode, mysqlmcpserver constructs SseServerTransport without passing securitysettings. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route.

Trigger condition: MCPTRANSPORT=sse. The default stdio mode is not affected.

Attack Scenarios

Scenario A — Direct exposure: Any network attacker can invoke executesql to run arbitrary SQL without credentials → full data dump, and via MySQL FILE privileges, arbitrary file read/write and RCE.

Scenario B — DNS rebinding (local bind): An attacker lures a victim's browser to a malicious page, rebinds their domain to 127.0.0.1, and uses the browser as a proxy to invoke executesql as same-origin.

Root Cause

In src/mysqlmcpserver/server.py:

1. SseServerTransport is constructed without securitysettings — the SDK defaults enablednsrebindingprotection to False. 2. The Starlette app has no CORS or TrustedHost middleware. 3. All three routes (/, /sse, /messages/) are unauthenticated. 4. The service binds to 0.0.0.0 by default. 5. The sink is cursor.execute(query) with a fully attacker-controlled query.

Impact

- Unauthenticated arbitrary SQL execution against the configured database - Full data exfiltration and modification - If the MySQL account holds FILE privilege: arbitrary file read (LOADFILE) and write (INTO OUTFILE) — potential RCE via webshell drop - Internet-wide scanning has identified 25 publicly reachable SSE instances of this project

Fix

Released in v0.4.2: DNS-rebinding protection is now enabled by passing TransportSecuritySettings(enablednsrebindingprotection=True) to SseServerTransport, and the documented recommended bind address is 127.0.0.1.

Credits

Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).

Affected Software

1 affected componentFixes available
pip/mysql-mcp-server<0.4.2
0.4.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/mysql-mcp-server to a version that resolves this vulnerability.

    Fixed in 0.4.2
  2. Upgrade

    Upgrade mysql_mcp_server to a version that resolves this vulnerability.

    Fixed in v0.4.2
  3. Configuration

    In SSE/HTTP transport mode, construct `SseServerTransport` with `TransportSecuritySettings(enable_dns_rebinding_protection=True)` so DNS-rebinding protection is enabled (the issue occurs when `SseServerTransport` is constructed without `security_settings`).

    SseServerTransport (MCP Python SDK) enable_dns_rebinding_protection = true
  4. Configuration

    Add Starlette middleware for CORS and TrustedHost validation (the text states the Starlette app has no CORS or TrustedHost middleware).

    Starlette application CORS middleware / TrustedHost middleware = none
  5. Configuration

    Change the service bind address from the default `0.0.0.0` to the documented recommended bind address `127.0.0.1` to mitigate the direct exposure/DNS-rebinding attack surface.

    MySQL MCP server bind address bind to = 127.0.0.1

Event History

Sep 11, 2026
Advisory Published
via GitHub·08:35 PM
Data Sourced
via GitHub·08:35 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using mysql_mcp_server with MCP_TRANSPORT=sse are affected. The default stdio transport mode is not affected; SSE mode binds to 0.0.0.0 by default and exposes unauthenticated routes.

2

What does an attacker need to exploit the directly exposed service?

A network attacker can invoke execute_sql without credentials when the SSE service is reachable. This enables arbitrary SQL execution, potentially including data disclosure and, where the MySQL account has FILE privileges, arbitrary file read/write and RCE.

3

Can a service bound only to localhost still be attacked?

Yes. An attacker can use DNS rebinding to cause a victim's browser to access a service at 127.0.0.1 and invoke execute_sql through the browser, because Origin and Host validation are disabled.

4

How can I determine whether my deployment is affected?

Check whether MCP_TRANSPORT is set to sse. In that mode, the affected application exposes the /, /sse, and /messages/ routes without authentication and lacks the described DNS-rebinding protections.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203