CVE-2026-85788
Awaiting Analysis Awaiting Analysis - Queue

SQL Injection Bypass in AWS Labs MySQL-MCP-Server

Vulnerability report for CVE-2026-85788, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: AMZN

Description

Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To remediate this issue, users should upgrade to version 1.0.23.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
amazon aws-labs_mysql-mcp-server 1.0.23
awslabs mysql-mcp-server to 1.0.23 (exc)
awslabs mysql-mcp-server 1.0.23

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-85788 is a vulnerability in the awslabs.mysql-mcp-server where SQL inline comments can bypass read-only enforcement. The server's detector fails to block certain SQL statements when comments are used, allowing file-read and file-write operations despite the read-only setting.

Detection Guidance

Detection involves checking the version of awslabs.mysql-mcp-server. Run: pip show mysql-mcp-server or check the version in your deployment logs. If the version is 1.0.21 or earlier, the system is vulnerable.

Impact Analysis

This vulnerability could allow an attacker to execute unauthorized SQL operations if they can influence the SQL string, such as through prompt injection. However, it requires the database user to have excessive privileges like FILE. Upgrading to version 1.0.23 or later mitigates this risk.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR or HIPAA if it leads to unauthorized data access or modification. The issue allows bypassing read-only enforcement, which might enable unauthorized file reads or writes if the database user has excessive privileges like FILE. However, the vulnerability's impact depends on the database user's permissions and is mitigated by ensuring least privilege access.

Mitigation Strategies
  • Upgrade awslabs.mysql-mcp-server to version 1.0.23 or later immediately.
  • Review and restrict database user privileges to the minimum required, removing unnecessary permissions like FILE.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85788. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart