Executive brief
mcp-pinot is a server component used to interface with Apache Pinot clusters. In its default configuration, the server is accessible to anyone on the network without a password. An attacker can exploit this to read sensitive data, modify database schemas, or disrupt the availability of the connected Pinot cluster by using the server's own administrative credentials.
Technical details
The vulnerability arises from three default configuration settings: OAuth authentication is disabled by default, the HTTP server binds to 0.0.0.0 (all interfaces), and the server uses its own privileged Pinot credentials to execute requests from any caller. This creates a 'confused deputy' scenario where an unauthenticated network-adjacent attacker can invoke any of the 14 registered MCP tools. Impacted tools include 'read_query' for arbitrary data access and 'create_schema'/'update_table_config' for cluster mutation. The issue is fixed in version 3.1.0 by changing the default bind to 127.0.0.1 and requiring OAuth for non-loopback connections.
Affected products
- StarTree mcp-pinot-server <= 3.0.1
Timeline
- 2026-05-23: disclosed: Disclosed via GitHub Security Advisory
- 2026-05-25: patched: Fixed in v3.1.0 and PR #95 merged
- 2026-05-25: advisory: GitHub Advisory published