Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in the MySQL MCP Server, a component used for secure database interactions. The issue, present in versions prior to 0.4.2, could allow unauthenticated network attackers to access, modify, or even execute code via the database. While the default transport method is unaffected, misconfigurations enabling network access could lead to significant data compromise and potential system control.
- Unsecured database access allows data theft or changes.
- Critical flaw impacts secure database interaction components.
- Confirm relevance and exposure to sensitive data.
Attack Path
How an attacker could exploit the issue
A network attacker can reach the MySQL MCP Server without authentication, either directly or by tricking a user's browser into sending requests through DNS rebinding. This allows the attacker to execute arbitrary SQL queries through the `cursor.execute()` function. If the database account has file privileges, the attacker could potentially read or write server files, leading to code execution.
- No authentication required.
- Execute arbitrary SQL queries.
- Disclosure, modification, and code execution.
Live Threat
Current exploitation, exposure, and threat context
A network attacker could exploit this vulnerability to directly execute SQL queries, potentially leading to unauthorized access and modification of the configured database. If the MySQL account has FILE privileges, this could extend to reading or writing server files, and possibly enable code execution.
- Database and server files at risk.
- Unauthenticated network access to execute SQL.
- Unauthorized data access, modification, or code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The MySQL MCP Server, when configured with `MCP_TRANSPORT=sse`, is susceptible to unauthenticated database disclosure and modification, with potential for file system access and code execution if the MySQL account has FILE privileges. Ownership likely falls to application or platform teams responsible for the MySQL MCP Server instances, with initial triage focusing on identifying all deployments, assessing their network exposure and criticality, and confirming the accountable owner for remediation planning.
- Application or platform teams own the issue.
- Verify network exposure and criticality first.
- Plan remediation based on verified risk.