Bug hunter tracks down three massive MCP flaws and one vendor won't fix theirs
Briefly

Bug hunter tracks down three massive MCP flaws and one vendor won't fix theirs
"Security vulnerabilities in MCP servers for three popular database projects could let attackers execute unintended SQL statements on Apache Doris, exfiltrate sensitive metadata from Alibaba RDS, and potentially take over Apache Pinot instances exposed to the internet. Alibaba, meanwhile, declined to patch its flaw."
""There is missing or faulty security validation between the MCP server and its back end," Peled wrote, adding that these security "gaps will become high-value targets for attackers and we expect more of these issues to surface.""
"Apache issued a patch and a CVE tracker for Doris MCP, and there's an open ticket in the MCP Pinot Github repository for the flaw, we're told. However, Alibaba decided not to patch the vulnerability in RDS MCP, according to Akamai security analyst Tomer Peled, who wrote about the flaws on Tuesday and will present his full research next month at x33fcon."
"Apache Doris is a high-speed analytics and search database with more than 10,000 mid- and large-enterprise users. Its MCP server allows AI agents to interact with and perform operations on Doris instances. This includes SQL queries or retrieving table and schema metadata - and foreshadows the found flaw: CVE-2025-66335, a SQL injection vulnerability, that affects Apache Doris MCP Server versions earlier than 0.6.1."
Security vulnerabilities in MCP servers for Apache Doris, Alibaba RDS, and Apache Pinot could allow attackers to execute unintended SQL statements, exfiltrate sensitive metadata, and potentially take over Pinot instances exposed to the internet. Apache issued a patch and a CVE tracker for the Doris MCP flaw, and an open ticket exists for the Pinot MCP issue. Alibaba declined to patch the vulnerability in RDS MCP. MCP is an open source protocol that lets LLMs and AI agents connect to external data and systems. The flaws point to a broader development problem: missing or faulty security validation between an MCP server and its back end, creating high-value targets for attackers and likely more issues in the future.
Read at theregister
Unable to calculate read time
[
|
]