VDB
Sign up
CRITICAL10.0

GHSA-rqfv-2mw9-78g2

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

Quick fix

GHSA-rqfv-2mw9-78g2 — mysql-mcp-server: upgrade to the fixed version with the command below.

pip install --upgrade 'mysql-mcp-server>=0.4.2'

Details

## Summary

In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to `0.0.0.0` by default with no authentication on any route.

**Trigger condition:** `MCP_TRANSPORT=sse`. The default stdio mode is not affected.

## Attack Scenarios

**Scenario A — Direct exposure:** Any network attacker can invoke `execute_sql` to run arbitrary SQL without credentials → full data dump, and via MySQL `FILE` privileges, arbitrary file read/write and RCE.

**Scenario B — DNS rebinding (local bind):** An attacker lures a victim's browser to a malicious page, rebinds their domain to `127.0.0.1`, and uses the browser as a proxy to invoke `execute_sql` as same-origin.

## Root Cause

In `src/mysql_mcp_server/server.py`:

1. `SseServerTransport` is constructed without `security_settings` — the SDK defaults `enable_dns_rebinding_protection` to `False`. 2. The Starlette app has no CORS or TrustedHost middleware. 3. All three routes (`/`, `/sse`, `/messages/`) are unauthenticated. 4. The service binds to `0.0.0.0` by default. 5. The sink is `cursor.execute(query)` with a fully attacker-controlled query.

## Impact

- Unauthenticated arbitrary SQL execution against the configured database - Full data exfiltration and modification - If the MySQL account holds `FILE` privilege: arbitrary file read (`LOAD_FILE`) and write (`INTO OUTFILE`) — potential RCE via webshell drop - Internet-wide scanning has identified 25 publicly reachable SSE instances of this project

## Fix

Released in v0.4.2: DNS-rebinding protection is now enabled by passing `TransportSecuritySettings(enable_dns_rebinding_protection=True)` to `SseServerTransport`, and the documented recommended bind address is `127.0.0.1`.

## Credits

Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mysql-mcp-server
Introduced in: 0Fixed in: 0.4.2
Fixpip install --upgrade 'mysql-mcp-server>=0.4.2'

References