Executive brief
A vulnerability exists in the Dynatrace Model Context Protocol (MCP) server, which is used to connect AI models to Dynatrace monitoring data. An attacker can manipulate input parameters to bypass security restrictions, such as time limits and data filters, that are normally enforced on 'read-only' tools. This could allow an AI agent or a user to access more monitoring data than intended, potentially exposing sensitive system information.
Technical details
A DQL (Dynatrace Query Language) injection vulnerability exists in @dynatrace-oss/dynatrace-mcp-server due to improper neutralization of special elements in data query logic (CWE-943). Several capabilities, including monitored entity lookups and event listing, interpolate user-supplied parameters (like entityNames, timeframe, and clusterId) directly into DQL query strings without escaping. An attacker can use quote characters to break out of string literals and append arbitrary DQL pipeline stages or use line comments (//) to truncate the original query. While the impact is limited to the permissions of the operator's token, it allows bypassing tool-specific constraints like 'readOnlyHint' auto-approvals and field filtering. The issue is fixed in version 2.1.1.
Affected products
- Dynatrace @dynatrace-oss/dynatrace-mcp-server < 2.1.1
Timeline
- 2026-06-09: disclosed
- 2026-07-31: advisory
- 2026-07-31: patched
References
- https://api.github.com/users/yotampe-pluto
- https://github.com/yotampe-pluto
- https://api.github.com/users/yotampe-pluto/gists%7B/gist_id%7D
- https://api.github.com/users/yotampe-pluto/repos
- https://avatars.githubusercontent.com/u/252890338?v=4
- https://api.github.com/users/yotampe-pluto/events%7B/privacy%7D