Description
Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace.



To remediate this issue, users should upgrade to version 1.0.23.
Published: 2026-09-09
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Read‑only enforcement bypass allowing file‑read and file‑write via SQL inline comments
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in an incomplete list of disallowed inputs within the mutable SQL detector of AWS Labs MySQL MCP Server, a flaw that corresponds to CWE‑184. The regex engine fails to treat certain SQL inline comments as whitespace, letting context‑dependent actors bypass the read‑only enforcement gate and reach file‑read and file‑write SQL sinks. This flaw could be used to read or modify files through SQL queries that the detector incorrectly accepts, potentially compromising data confidentiality and integrity if the attacker can inject such queries.

Affected Systems

All versions of AWS Labs MySQL MCP Server prior to the 1.0.23 release are affected. The vulnerability exists in the mutable SQL detector component, which is part of the open‑source MCP Server repository maintained by AWS Labs. Vendors or customers relying on earlier MCP Server releases should confirm that their installation matches or predates the 1.0.23 version.

Risk and Exploitability

The CVSS score of 5.7 indicates a moderate severity, and the EPSS score is not available, suggesting no current publicly known exploitation. Because the flaw requires injection of SQL with inline comments and access to the MCC Server’s SQL interface, successful exploitation would depend on the server being exposed to untrusted input. The issue is not listed in CISA’s KEV catalog, so an active warehouse exploitation is not yet documented. Nonetheless, the possibility of bypassing read‑only controls to read or write files necessitates prompt remediation.

Generated by OpenCVE AI on September 9, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AWS Labs MySQL MCP Server to version 1.0.23 or later, which corrects the regex handling flaw identified as CWE‑184.
  • After updating, test SQL ingestion paths that use inline comments to verify file‑read and file‑write sinks are no longer reachable.
  • Review configuration and enforce strict input validation or use parameterized queries to reduce the attack surface, addressing the weakness highlighted by CWE‑184.

Generated by OpenCVE AI on September 9, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To remediate this issue, users should upgrade to version 1.0.23.
Title Incomplete list of disallowed inputs in awslabs mysql-mcp-server
First Time appeared Aws
Aws aws Labs Mysql Mcp Server
Weaknesses CWE-184
CPEs cpe:2.3:a:aws:aws_labs_mysql_mcp_server:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws aws Labs Mysql Mcp Server
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Aws Aws Labs Mysql Mcp Server
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-09T19:00:19.205Z

Reserved: 2026-09-04T17:19:34.906Z

Link: CVE-2026-85788

cve-icon Vulnrichment

Updated: 2026-09-09T19:00:13.064Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T17:17:49.937

Modified: 2026-09-09T20:13:26.720

Link: CVE-2026-85788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:30:16Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs