Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/odp0fyyst8kxm7hhm9z4d1snh1y4hjpy | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/17/4 | Mailing List |
Configurations
History
22 Apr 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://lists.apache.org/thread/odp0fyyst8kxm7hhm9z4d1snh1y4hjpy - Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/04/17/4 - Mailing List | |
| CPE | cpe:2.3:a:apache:doris_mcp_server:*:*:*:*:*:*:*:* | |
| First Time |
Apache doris Mcp Server
Apache |
20 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
20 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-20 14:16
Updated : 2026-04-22 14:17
NVD link : CVE-2025-66335
Mitre link : CVE-2025-66335
CVE.ORG link : CVE-2025-66335
JSON object : View
Products Affected
apache
- doris_mcp_server
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
