Junglewise Threat Intelligence

CVE-2025-66336: Apache Doris MCP Server SQL injection in metadata query path

CVE-2025-66336 · Severity: high · CVSS 8.1 · Published 2026-06-22

Technologies: doris-mcp-server (PyPI). Vendors: PyPI, Apache.

Executive brief

Apache Doris MCP Server is a metadata access service that allows users to query database information. A SQL injection vulnerability allows authenticated users (or anonymous users if authentication is disabled) to bypass security controls and access metadata from databases they should not be able to reach. An attacker could view or modify sensitive database metadata across the entire system.

Technical details

The vulnerability is a classic SQL injection (CWE-89) in the metadata query path where user-supplied database names are directly concatenated into SQL queries without parameterization or escaping. The root cause is improper input validation and the execution of queries without passing the caller's authorization context, allowing privilege escalation. An authenticated attacker (or anonymous attacker if authentication is disabled) can craft malicious database name input to modify the SQL query logic and access metadata from databases outside their authorization scope. The attack requires network access to the MCP server endpoint and can be exploited with low complexity. The vulnerability has high impact on confidentiality (unauthorized metadata disclosure) and integrity (potential metadata modification). A fix is available in version 0.6.1 and later, implemented via PR #68 which adds proper parameterization and authorization context validation.

Affected products

  • Apache Doris MCP Server < 0.6.1

Timeline

  • 2026-06-22: disclosed: Vulnerability published in GitHub Advisory Database and NVD
  • 2026-06-22: patched: Fix available in version 0.6.1

References

Related threats