Executive brief
The @executeautomation/database-server is an MCP (Model Context Protocol) server used to provide AI agents and workflows with database query capabilities. The server claims to enforce "read-only" mode by checking if queries start with "SELECT", but this check is insufficient to prevent dangerous database operations. Attackers with authenticated access can use functions like pg_terminate_backend() or execute stored procedures to disrupt database availability, leak sensitive data about running queries, or cause service outages.
Technical details
The vulnerability is an improper access control issue (CWE-284) stemming from a naive string-matching check (startsWith("SELECT")) used to enforce "read-only" mode in the read_query tool. The vulnerable code fails to recognize that PostgreSQL and other databases allow side-effects and administrative operations through SELECT statements—including stored procedures, pg_terminate_backend() to kill connections, and other functions. An authenticated attacker can execute queries like "SELECT pg_terminate_backend(pid)" to cause denial of service or "SELECT some_function_that_updates_data()" to bypass the read-only guarantee. The PostgreSQL pg driver also supports multi-statement queries separated by semicolons, further weakening the defense. No patch has been released as of the advisory date.
Affected products
- ExecuteAutomation database-server <=1.1.0
Timeline
- 2025-09-16: disclosed