CVE-2025-66335
published 2026-04-20CVE-2025-66335: Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.66%
47.2th percentile
Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | doris_mcp_server | >= 0.1.0 < 0.6.1 | 0.6.1 |
| apache_software_foundation | apache_doris_mcp_server | >= 0.1.0 < 0.6.1 | 0.6.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
ghsa·2026-04-20
CVE-2025-66335 [MEDIUM] CWE-89 Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
Apache Doris MCP Server versions prior to 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Versions 0.6.1 and later are not affected.
GHSA
GHSA-qhfq-gvvc-5q6q: Apache Doris MCP Server versions earlier than 0
ghsa_unreviewed·2026-04-20
CVE-2025-66335 [MEDIUM] CWE-89 GHSA-qhfq-gvvc-5q6q: Apache Doris MCP Server versions earlier than 0
Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.
VulDB
Apache Doris MCP Server up to 0.6.0 sql injection
vuldb·2026-04-17
CVE-2025-66335 [CRITICAL] Apache Doris MCP Server up to 0.6.0 sql injection
A vulnerability was found in Apache Doris MCP Server up to 0.6.0. It has been rated as critical. The impacted element is an unknown function. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2025-66335. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
2026-04-20
Published