Impact
Without origin or host validation, the MySQL MCP server’s SSE transport exposes its execute_sql endpoint to anyone who can reach the service. An attacker who can reach the host directly, or who can trick a victim’s browser into performing same‑origin requests via DNS rebinding, can submit arbitrary SQL queries. This allows full reading and alteration of the configured MySQL database, and if the database account has FILE privileges, reading or writing arbitrary files on the server and potentially executing code. The weakness is a lack of authentication (CWE‑306) and missing origin validation (CWE‑346).
Affected Systems
All versions of designcomputer MySQL MCP Server released before 0.4.2 are vulnerable. The default transport that binds to 0.0.0.0 is the affected configuration; the stdio transport is unaffected.
Risk and Exploitability
With a CVSS score of 10, the vulnerability is classified as critical. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. An attacker could exploit it via direct network access to the SSE endpoints or via a browser exploiting DNS rebinding to send requests to the locally bound service. No special user privileges are required on the client side, and the impact spans confidentiality, integrity, and potentially availability of the database and underlying server.
OpenCVE Enrichment
Github GHSA