Executive brief
The Dynatrace Model Context Protocol (MCP) Server is a bridge that allows AI assistants and other applications to query monitoring data. A vulnerability allows attackers to inject malicious DQL (Dynatrace Query Language) commands through tool parameters that should accept only identifiers or time values, bypassing safety restrictions like field limits and time windows. This could enable unauthorized data access or allow AI systems to be tricked into exposing monitoring secrets through prompt injection.
Technical details
The vulnerability is a DQL (Dynatrace Query Language) injection in several read-only tools. Multiple capabilities (find-monitored-entity-by-name, list-problems, list-vulnerabilities, list-exceptions, get-events-for-cluster) directly interpolate unsanitized user-supplied parameters into DQL query strings without quoting or escaping. Parameters documented as identifiers or constrained values (e.g., "24h" timeframe, Kubernetes UIDs) are concatenated directly into DQL queries, allowing attackers to break out of string literals using quote characters and inject arbitrary DQL pipeline stages. Exploitation requires user interaction (MCP client interaction or LLM prompt injection) and no authentication, but is limited to information disclosure through bypassing the tools' field-scope and time-window restrictions. The fix involves proper parameter validation and quoting; patched versions v2.1.1 and newer are available.
Affected products
- Dynatrace dynatrace-mcp-server up to and including 1.8.5
Timeline
- 2026-07-31: disclosed: Advisory published
- 2026-07-31: patched: Fix released in v2.1.1 and newer