Severity: important 

Affected versions:

- Apache Doris MCP Server 0.1.0 before 0.6.1

Description:

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata 
query path. A user-controlled database name is directly interpolated into a SQL 
query, and the query is executed without passing the caller's authorization 
context. This may allow an authenticated attacker, or an anonymous attacker if 
authentication is disabled, to bypass SQL security validation and access 
metadata outside the intended database scope.

Affected users are recommended to upgrade to Doris version 0.6.1 or later, 
which fixes the issue.

Credit:

cherno.x. (reporter)

References:

https://doris.apache.org
https://www.cve.org/CVERecord?id=CVE-2025-66336

Reply via email to