High severity8.1NVD Advisory· Published Sep 16, 2025· Updated Jun 17, 2026
CVE-2025-59333
CVE-2025-59333
Description
The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result, the server is susceptible to abuse and attacks on affected database systems such as PostgreSQL, and potentially others that expose elevated functionalities. These attacks may lead to denial of service and other unexpected behaviors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@executeautomation/database-servernpm | <= 1.1.0 | — |
Affected products
3cpe:2.3:a:executeautomation:mcp_database_server:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:executeautomation:mcp_database_server:*:*:*:*:*:node.js:*:*range: <=1.1.0
- (no CPE)range: <= 1.1.0
Patches
Vulnerability mechanics
References
3- github.com/executeautomation/mcp-database-server/security/advisories/GHSA-65hm-pwj5-73pwnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-65hm-pwj5-73pwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-59333ghsaADVISORY
News mentions
0No linked articles in our index yet.