A AegiFlow
LOWCVSS 2.1EPSS 0.2%

CVE-2026-11529

CVE-2026-11529 updated by NVD

Published
2026-06-08
Modified
2026-07-25
EPSS percentile
11%
Sources
github-advisory, nvd

Summary

A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.3.0 is sufficient to resolve this issue. Patch name: 080bef9a96d625ce0dfbde573a08b93497871981. Upgrading the affected component is advised.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPImysql-mcp-server0.3.0

Remediation: Upgrade to 0.3.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.