Логотип exploitDog
bind:CVE-2025-59333
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-59333

Количество 2

Количество 2

nvd логотип

CVE-2025-59333

5 месяцев назад

The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result, the server is susceptible to abuse and attacks on affected database systems such as PostgreSQL, and potentially others that expose elevated functionalities. These attacks may lead to denial of service and other unexpected behaviors.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-65hm-pwj5-73pw

5 месяцев назад

@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-59333

The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result, the server is susceptible to abuse and attacks on affected database systems such as PostgreSQL, and potentially others that expose elevated functionalities. These attacks may lead to denial of service and other unexpected behaviors.

CVSS3: 8.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-65hm-pwj5-73pw

@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode

CVSS3: 8.1
0%
Низкий
5 месяцев назад

Уязвимостей на страницу