CVE-2026-85788 PUBLISHED

Incomplete list of disallowed inputs in awslabs mysql-mcp-server

Assigner: AMZN
Reserved: 04.09.2026 Published: 09.09.2026 Updated: 09.09.2026

Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace.

To remediate this issue, users should upgrade to version 1.0.23.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.7

Product Status

Vendor AWS
Product AWS Labs MySQL MCP Server
Versions Default: unaffected
  • affected from 0 to 1.0.21 (incl.)

References

Problem Types

  • CWE-184 Incomplete list of disallowed inputs CWE

Impacts

  • CAPEC-120 Double Encoding