Junglewise Threat Intelligence

CVE-2026-7206: dubydu sqlite-mcp SQL injection and path traversal in extract_to_json

CVE-2026-7206 · Severity: high · CVSS 7.3 · Published 2026-04-28

Vendors: PyPI.

Executive brief

A security vulnerability was found in dubydu sqlite-mcp, a tool that allows AI models to interact with SQLite databases. An attacker can exploit this flaw to perform unauthorized database operations or write data to unintended locations on the server's file system. This could lead to the exposure of sensitive information or the corruption of system files.

Technical details

The vulnerability exists in the `extract_to_json` function within `src/entry.py` of dubydu sqlite-mcp versions up to 0.1.0. The function fails to properly sanitize the `output_filename` and `table_name` arguments. An attacker can provide a manipulated `output_filename` containing directory traversal sequences (e.g., `../`) to write JSON-formatted database exports to arbitrary locations on the filesystem. Additionally, the lack of validation on the `table_name` parameter allows for SQL injection. These issues can be exploited remotely without authentication if the MCP server is exposed. A patch (commit a5580cb) has been released which implements `os.path.basename()` for filename sanitization and adds validation for table names.

Affected products

  • dubydu sqlite-mcp up to 0.1.0

Timeline

  • 2026-04-10: disclosed: Issue reported via GitHub and patch submitted via PR #2
  • 2026-04-10: patched: Patch committed in a5580cb992f4f6c308c9ffe6442b2e76709db548
  • 2026-04-28: advisory: NVD publication date

References