CVE-2026-61788
Description
DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting readonly = true on the execute_sql tool does not make the connection read-only. The connectors are written to set PostgreSQL default_transaction_read_only=on (and open SQLite in readOnly mode), but that code is gated on a config value that is never populated, so it never runs. The only thing left enforcing read-only is a classifier that inspects the first keyword of each statement. Any SELECT that writes or has side effects through a function call passes it. With an ordinary role this allows sequence tampering; with a privileged role it allows writing arbitrary files on the server (lo_export), reading arbitrary host files (pg_read_file), and remote code execution (dblink + COPY ... TO PROGRAM). The HTTP transport is unauthenticated and binds to 0.0.0.0 by default, so this is reachable by any network caller of /mcp. Version 0.22.6 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-mwwr-p57h-56pfghsaADVISORY
- github.com/bytebase/dbhub/commit/872bb338f7d31f6afe517a076ac3e3edafaaaf08ghsa
- github.com/bytebase/dbhub/pull/342ghsa
- github.com/bytebase/dbhub/releases/tag/v0.22.6ghsa
- github.com/bytebase/dbhub/security/advisories/GHSA-mwwr-p57h-56pfnvd
- nvd.nist.gov/vuln/detail/CVE-2026-61788ghsa
News mentions
0No linked articles in our index yet.