CVE-2026-59971
CRITICALCVE-2026-59971 is a critical-severity (CVSS 10) remote code execution vulnerability in mysql-mcp-server. O3 Security confirms whether CVE-2026-59971 is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
Real-World Exposure
mysql-mcp-serverReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Summary
In SSE/HTTP transport mode, mysql_mcp_server constructs SseServerTransport without passing security_settings. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route.
Trigger condition: MCP_TRANSPORT=sse. The default stdio mode is not affected.
Attack Scenarios
Scenario A — Direct exposure: Any network attacker can invoke execute_sql to run arbitrary SQL without credentials → full data dump, and via MySQL FILE privileges, arbitrary file read/write and RCE.
Scenario B — DNS rebinding (local bind): An attacker lures a victim's browser to a malicious page, rebinds their domain to 127.0.0.1, and uses the browser as a proxy to invoke execute_sql as same-origin.
Root Cause
In src/mysql_mcp_server/server.py:
SseServerTransportis constructed withoutsecurity_settings— the SDK defaultsenable_dns_rebinding_protectiontoFalse.- The Starlette app has no CORS or TrustedHost middleware.
- All three routes (
/,/sse,/messages/) are unauthenticated. - The service binds to
0.0.0.0by default. - The sink is
cursor.execute(query)with a fully attacker-controlled query.
Impact
- Unauthenticated arbitrary SQL execution against the configured database
- Full data exfiltration and modification
- If the MySQL account holds
FILEprivilege: arbitrary file read (LOAD_FILE) and write (INTO OUTFILE) — potential RCE via webshell drop - Internet-wide scanning has identified 25 publicly reachable SSE instances of this project
Fix
Released in v0.4.2: DNS-rebinding protection is now enabled by passing TransportSecuritySettings(enable_dns_rebinding_protection=True) to SseServerTransport, and the documented recommended bind address is 127.0.0.1.
Credits
Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | mysql-mcp-server | all versions | 0.4.2 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for mysql-mcp-server. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.
Fix
Update mysql-mcp-server to 0.4.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-59971 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 pinpoints whether CVE-2026-59971 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.
Tailored to CVE-2026-59971. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2026-59971 in your dependencies?
O3 detects CVE-2026-59971 across PyPI dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.