VYPR

Bytebase

by Bytebase

Source repositories

CVEs (5)

  • CVE-2026-79536CriSep 29, 2026
    risk 0.59cvss 9.1epss 0.00

    bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.

  • CVE-2026-61742CriSep 24, 2026
    risk 0.53cvss —epss 0.00

    DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport http --port 8080`. The HTTP server…

  • CVE-2026-61788HigSep 24, 2026
    risk 0.41cvss 7.4epss 0.00

    DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to set PostgreSQL…

  • CVE-2022-32170MedSep 28, 2022
    risk 0.28cvss 4.3epss 0.01

    The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.

  • CVE-2022-32169MedSep 28, 2022
    risk 0.28cvss 4.3epss 0.01

    The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.

VYPR — Vulnerability Intelligence