Kestrel
대시보드로 돌아가기
CVE-2026-59971CRITICAL· 10.0GHSA대응게시일: 2026. 09. 11.수정일: 2026. 09. 11.

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

위협 신호 · CVSS · EPSS · KEV

시급 검토· 이론 심각도 Critical
CVSS
10.0critical

이론적 심각도 점수

EPSS

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한3일 이내CISA SSVC 기준

즉시(3일 이내) 패치 — 최우선 대응

자동화 가능완전 장악외부 노출· KEV 미등재 · 자동화 가능 · 완전 장악 · 외부 노출

CVSS 벡터 · 메트릭

악용 경로
공격 벡터네트워크
공격 복잡도낮음
필요 권한불필요
사용자 상호작용불필요
범위변경
영향
기밀성 영향높음
무결성 영향높음
가용성 영향높음
버전별 점수
CVSS 3.110.0CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

상세 설명

Summary

In SSE/HTTP transport mode, mysql_mcp_server constructs SseServerTransport without passing security_settings. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route.

Trigger condition: MCP_TRANSPORT=sse. The default stdio mode is not affected.

Attack Scenarios

Scenario A — Direct exposure: Any network attacker can invoke execute_sql to run arbitrary SQL without credentials → full data dump, and via MySQL FILE privileges, arbitrary file read/write and RCE.

Scenario B — DNS rebinding (local bind): An attacker lures a victim's browser to a malicious page, rebinds their domain to 127.0.0.1, and uses the browser as a proxy to invoke execute_sql as same-origin.

Root Cause

In src/mysql_mcp_server/server.py:

  1. SseServerTransport is constructed without security_settings — the SDK defaults enable_dns_rebinding_protection to False.
  2. The Starlette app has no CORS or TrustedHost middleware.
  3. All three routes (/, /sse, /messages/) are unauthenticated.
  4. The service binds to 0.0.0.0 by default.
  5. The sink is cursor.execute(query) with a fully attacker-controlled query.

Impact

  • Unauthenticated arbitrary SQL execution against the configured database
  • Full data exfiltration and modification
  • If the MySQL account holds FILE privilege: arbitrary file read (LOAD_FILE) and write (INTO OUTFILE) — potential RCE via webshell drop
  • Internet-wide scanning has identified 25 publicly reachable SSE instances of this project

Fix

Released in v0.4.2: DNS-rebinding protection is now enabled by passing TransportSecuritySettings(enable_dns_rebinding_protection=True) to SseServerTransport, and the documented recommended bind address is 127.0.0.1.

Credits

Discovered by Huanchen, SongWu (JHU), and BrookeYangRui (JHU).

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.