Home

Description

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.

PUBLISHED Reserved 2025-11-27 | Published 2026-04-20 | Updated 2026-04-20 | Assigner apache

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

0.1.0 (semver) before 0.6.1
affected

Credits

Tomer Peled, Senior Security Researcher at Akamai reporter

References

www.openwall.com/lists/oss-security/2026/04/17/4

lists.apache.org/thread/odp0fyyst8kxm7hhm9z4d1snh1y4hjpy vendor-advisory

cve.org (CVE-2025-66335)

nvd.nist.gov (CVE-2025-66335)

Download JSON