{"id":"CVE-2026-59971","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-59971","summary":"MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)","details":"## Summary\n\nIn SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route.\n\n**Trigger condition:** `MCP_TRANSPORT=sse`. The default stdio mode is not affected.\n\n## Attack Scenarios\n\n**Scenario A — Direct exposure:** Any network attacker can invoke `execute_sql` to run arbitrary SQL without credentials → full data dump, and via MySQL `FILE` privileges, arbitrary file read/write and RCE.\n\n**Scenario B — DNS rebinding (local bind):** An attacker lures a victim's browser to a malicious page, rebinds their domain to `127.0.0.1`, and uses the browser as a proxy to invoke `execute_sql` as same-origin.\n\n## Root Cause\n\nIn `src/mysql_mcp_server/server.py`:\n\n1. `SseServerTransport` is constructed without `security_settings` — the SDK defaults `enable_dns_rebinding_protection` to `False`.\n2. The Starlette app has no CORS or TrustedHost middleware.\n3. All three routes (`/`, `/sse`, `/messages/`) are unauthenticated.\n4. The service binds to `0.0.0.0` by default.\n5. The sink is `cursor.execute(query)` with a fully attacker-controlled query.\n\n## Impact\n\n- Unauthenticated arbitrary SQL execution against the configured database\n- Full data exfiltration and modification\n- If the MySQL account holds `FILE` privilege: arbitrary file read (`LOAD_FILE`) and write (`INTO OUTFILE`) — potential RCE via webshell drop\n- Internet-wide scanning has identified 25 publicly reachable SSE instances of this project\n\n## Fix\n\nReleased in v0.4.2: DNS-rebinding protection is now enabled by passing `TransportSecuritySettings(enable_dns_rebinding_protection=True)` to `SseServerTransport`, and the documented recommended bind address is `127.0.0.1`.\n\n## Credits\n\nDiscovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).","published":"2026-09-11T20:35:42Z","modified":"2026-09-11T20:45:04.756487465Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"mysql-mcp-server","fixedVersion":"0.4.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/designcomputer/mysql_mcp_server/security/advisories/GHSA-rqfv-2mw9-78g2"},{"type":"WEB","url":"https://github.com/designcomputer/mysql_mcp_server/issues/92"},{"type":"PACKAGE","url":"https://github.com/designcomputer/mysql_mcp_server"},{"type":"WEB","url":"https://github.com/designcomputer/mysql_mcp_server/releases/tag/v0.4.2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T20:45:04.756487465Z"}}