CVE-2025-66335

CVE-2025-66335: Apache Doris MCP Server: MCP SQL inject

Vendor Apache Software Foundation
Product Apache Doris MCP Server
Weakness CWE-89 · SQLi
Published April 20, 2026
Last update April 20, 2026

CVSS base score

What the vulnerability does

Description

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.

Key dates

Disclosure timeline

April 20, 2026 CVE published
April 20, 2026 Record updated