VYPR

mysql-mcp-server

by Amazon

CVEs (1)

  • CVE-2026-85788MedSep 9, 2026
    risk 0.29cvss 5.5epss

    Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine…