CVE-2025-66335 PUBLISHED

Apache Doris MCP Server: MCP SQL inject

Assigner: apache
Reserved: 27.11.2025 Published: 20.04.2026 Updated: 20.04.2026

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.

Product Status

Vendor Apache Software Foundation
Product Apache Doris MCP Server
Versions Default: unaffected
  • affected from 0.1.0 to 0.6.1 (excl.)

Credits

  • Tomer Peled, Senior Security Researcher at Akamai reporter

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE