Impact
The MCP server in Alibaba Cloud RDS OpenAPI is configured to bind its management endpoint to all network interfaces by default. This improper binding exposes the MCP tools to any remote host that can reach the listener, allowing an attacker to invoke these tools without authentication. The weakness is identified as CWE‑1188, an improper binding configuration that can lead to unauthorized command execution or data access through the exposed management interface.
Affected Systems
Alibaba Cloud RDS OpenAPI MCP Server is the vulnerable component. No specific affected versions are listed, indicating that any deployment configured with the default insecure binding—including those published on the public GitHub repository or the Alibaba Cloud marketplace—may be impacted.
Risk and Exploitability
The CVSS score of 5.8 classifies the issue as moderate, while the EPSS score of less than 1 % suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access; an attacker only needs connectivity to the MCP endpoint, which, by default, listens on all interfaces. If the endpoint is reachable from the internet or an external subnet, exploitation can occur without any authentication or privileged credentials.
OpenCVE Enrichment