Answer in brief
CVE-2026-59971 records a Critical severity (CVSS 10.0) vulnerability in MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure). The current sources do not mark it as known exploited. The current feed maps mysql-mcp-server (pip). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 10.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps mysql-mcp-server (pip). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| mysql-mcp-serverpip | <0.4.2 | 0.4.2 |
Published upstream
Sep 11, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
## Summary In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route. **Trigger condition:** `MCP_TRANSPORT=sse`. The default stdio mode is not affected. ## Attack Scenarios **Scenario A — Direct exposure:** Any network attacker can invoke `execute_sql` to run arbitrary SQL without credentials → full data dump, and via MySQL `FILE` privileges, arbitrary file read/write and RCE. **Scenario B — DNS rebinding (local bind):** An attacker lures a victim's browser to a malicious page, rebinds their domain to `127.0.0.1`, and uses the browser as a proxy to invoke `execute_sql` as same-origin. ## Root Cause In `src/mysql_mcp_server/server.py`: 1. `SseServerTransport` is constructed without `security_settings` — the SDK defaults `enable_dns_rebinding_protection` to `False`. 2. The Starlette app has no CORS or TrustedHost middleware. 3. All three routes (`/`, `/sse`, `/messages/`) are unauthenticated. 4. The service binds to `0.0.0.0` by default. 5. The sink is `cursor.execute(query)` with a fully attacker-controlled query. ## Impact - Unauthenticated arbitrary SQL execution against the configured database - Full data exfiltration and modification - If the MySQL account holds `FILE` privilege: arbitrary file read (`LOAD_FILE`) and write (`INTO OUTFILE`) — potential RCE via webshell drop - Internet-wide scanning has identified 25 publicly reachable SSE instances of this project ## Fix Released in v0.4.2: DNS-rebinding protection is now enabled by passing `TransportSecuritySettings(enable_dns_rebinding_protection=True)` to `SseServerTransport`, and the documented recommended bind address is `127.0.0.1`. ## Credits Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).
Quoted source text, attributed separately from HOL analysis.