Impact
The vulnerability lies in an incomplete list of disallowed inputs within the mutable SQL detector of AWS Labs MySQL MCP Server, a flaw that corresponds to CWE‑184. The regex engine fails to treat certain SQL inline comments as whitespace, letting context‑dependent actors bypass the read‑only enforcement gate and reach file‑read and file‑write SQL sinks. This flaw could be used to read or modify files through SQL queries that the detector incorrectly accepts, potentially compromising data confidentiality and integrity if the attacker can inject such queries.
Affected Systems
All versions of AWS Labs MySQL MCP Server prior to the 1.0.23 release are affected. The vulnerability exists in the mutable SQL detector component, which is part of the open‑source MCP Server repository maintained by AWS Labs. Vendors or customers relying on earlier MCP Server releases should confirm that their installation matches or predates the 1.0.23 version.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity, and the EPSS score is not available, suggesting no current publicly known exploitation. Because the flaw requires injection of SQL with inline comments and access to the MCC Server’s SQL interface, successful exploitation would depend on the server being exposed to untrusted input. The issue is not listed in CISA’s KEV catalog, so an active warehouse exploitation is not yet documented. Nonetheless, the possibility of bypassing read‑only controls to read or write files necessitates prompt remediation.
OpenCVE Enrichment