Skip to main content
QUIETLYTIC
Vulnerability

5 CVEs Across 3 Vendors (CVE-2026-59971)

Five 2026 MCP-server CVEs: unauthenticated SQL execution (CVSS 10) in MySQL MCP Server, a code-execution flaw in functype-mcp-server, and three CKAN issues.

CVE-2026-59971
Threat Level
CRITICAL
CVSS
10.0
Status
Monitored
Confidence
Medium
Affected Products
MySQL MCP Server, functype-mcp-server, CKAN MCP Server

Full CVE Roster

All 5 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search.

CVE ID Title CVSS Severity KEV
CVE-2026-59971 — 10.0 critical
CVE-2026-59176 — 7.8 high
CVE-2026-73846 — 6.5 medium
CVE-2026-73845 — 5.3 medium
CVE-2026-73844 — 3.7 low

Model Context Protocol (MCP) servers — the connectors that give LLM agents direct access to databases, package managers, and external APIs — are a fast-growing but still security-immature category. Five CVEs disclosed across three independent MCP server projects in September 2026 illustrate the pattern: an unauthenticated-by-default network transport, an unsanitized string handed to a package manager, and weak URL-allowlist regexes. All five trace to a single source in our ledger (GitHub Advisory Database), so confidence is medium throughout, and none carry any exploitation evidence.

CVE-2026-59971: MySQL MCP Server — unauthenticated SQL execution via missing origin validation

Affects mysql-mcp-server (PyPI) in SSE/HTTP transport mode, triggered when MCP_TRANSPORT=sse (the default stdio mode is unaffected). Per the GitHub Advisory Database record, the server constructs its SSE transport without passing the MCP Python SDK’s security settings, which leaves DNS-rebinding protection (Origin/Host header validation) disabled; the underlying Starlette application has no CORS or TrustedHost middleware; and the service binds to 0.0.0.0 by default with no authentication on any route. The practical effect: a network attacker who can reach the server can invoke its SQL-execution tool directly, with no credentials, to run arbitrary SQL against the configured database — and if the MySQL account in use holds FILE privilege, that extends to arbitrary file read and write, which the record notes can lead to remote code execution. A more constrained variant applies even when the server is bound only to localhost: an attacker can lure a victim’s browser to a malicious page and use DNS rebinding to make the browser act as a same-origin proxy into the local server. The record states an internet-wide scan identified 25 publicly reachable SSE instances of this project at disclosure time — we’re reporting that as the record’s own claim, not an independently verified count. CWE-306 (Missing Authentication for Critical Function) and CWE-346 (Origin Validation Error). CVSS base 10.0 (critical; vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Fixed in 0.4.2, which enables the SDK’s DNS-rebinding protection and documents 127.0.0.1 as the recommended bind address. Confidence: medium.

CVE-2026-59176: functype-mcp-server — code execution via an unvalidated version-string tool argument

Affects functype-mcp-server (npm); fixed in 1.4.4. Per the GitHub Advisory Database record, an MCP tool that lets a caller set the installed version of the functype package accepts an unconstrained string and interpolates it directly into a package specifier the server installs via its package manager, without validating the format or rejecting alternate resolution syntaxes. Because package-manager specifiers support resolution forms beyond a plain registry version — including installing from an arbitrary local path — a caller of this tool can cause the server to install a package of the caller’s choosing under the functype name. Immediately after that install, the server dynamically imports code from the newly installed package as part of its own documentation-refresh routine, executing the caller-controlled code inside the MCP server process. The record notes this tool requires no authentication and is enabled by default, and specifically warns that an AI agent connected to this server, if manipulated via a compromised document or web page (indirect prompt injection), could be induced to invoke the tool itself. CWE-829 (Inclusion of Functionality from Untrusted Control Sphere). CVSS base 7.8 (high; vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Fixed in 1.4.4. Confidence: medium.

CVE-2026-73846: CKAN MCP Server — cache-key collision enables cache poisoning

Affects @aborruso/ckan-mcp-server (npm) through 0.4.111. Per the GitHub Advisory Database record, the server’s response cache builds its lookup key by joining request parameters into a string without escaping the characters that format itself uses as field separators, so two different, unrelated parameter combinations can serialize to the identical cache key and share one cache entry. Whichever request populates the entry first determines what every subsequent colliding request receives — the record describes this as letting an attacker prime a colliding key so a different user’s distinct query returns the attacker’s cached result instead of its own. CWE-345 (Insufficient Verification of Data Authenticity) and CWE-436 (Interpretation Conflict). CVSS base 6.5 (medium; vector AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N). Fixed in 0.4.112. Confidence: medium.

CVE-2026-73845: CKAN MCP Server — allowlist bypass via an unanchored regex

Affects @aborruso/ckan-mcp-server through 0.4.111. Per the GitHub Advisory Database record, two of the server’s tools restrict which host they’ll contact using a regular expression meant to allow only the CKAN operator’s own domain, but the pattern is anchored only at the start of the string with no boundary marking where the allowed hostname ends. Any host whose name merely begins with the allowed domain — or that places the allowed domain before an “@” as URL userinfo, a distinct part of a URL from its actual host — satisfies that pattern while the request actually reaches a different, attacker-controlled host. CWE-20 (Improper Input Validation), CWE-625 (Permissive Regular Expression), and CWE-918 (SSRF). CVSS base 5.3 (medium; vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Fixed in 0.4.112. Confidence: medium.

CVE-2026-73844: CKAN MCP Server — internal detail disclosed via unsanitized error messages

Affects @aborruso/ckan-mcp-server through 0.4.111. Per the GitHub Advisory Database record, when the server’s upstream request path returns an unexpected response or throws an internal exception, the raw response body and exception message are returned to the caller verbatim rather than a generic, sanitized message — so a caller who can influence which host the server contacts can potentially retrieve internal hostnames, IP addresses, database error text, or stack-trace fragments from the resulting error response. CWE-209 (Information Exposure Through an Error Message) and CWE-210 (Information Exposure Through Self-Generated Error Message). CVSS base 3.7 (low; vector AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Fixed in 0.4.112. Confidence: medium.

Confidence and evidence gaps

Every CVE in this roundup traces to exactly one source — GitHub Advisory Database — so confidence stays medium across the board; none reach high without a second independent source agreeing. Worth naming directly: the “25 publicly reachable instances” figure for the MySQL MCP Server CVE is the advisory’s own scan claim, not something we’ve independently verified. The three CKAN MCP Server CVEs share the same fix release (0.4.112) despite being three distinct findings with different root causes, which reads as a single coordinated security review rather than three unrelated discoveries — an inference from the shared fix version, not a claim the record states outright.

Why this matters

MCP servers connect LLM agents directly to real infrastructure — databases, package managers, external APIs — and these five CVEs show a recurring pattern in a category that’s grown faster than its security practices have matured: transports that default to no authentication, string interpolation into a package manager with no format validation, and URL-allowlist regexes anchored at only one end. Teams wiring MCP servers into agent pipelines shouldn’t assume “runs on localhost” means safe by default (DNS rebinding defeats that assumption directly) or that a single regex check is sufficient allowlisting — both assumptions failed in this batch. The functype-mcp-server finding adds a second layer worth noting: an MCP tool doesn’t need a human attacker directly calling it to be dangerous if an AI agent connected to that server can be manipulated into calling it itself. That’s the same lesson as our vLLM security advisory roundup and Ollama’s KEV-listed out-of-bounds read: the self-hosted LLM infrastructure stack — model server, MCP connectors, and the agent tooling wired to both — needs the same security scrutiny as any other network-facing service, not less because an AI agent sits in front of it.

Frequently Asked Questions

Is any of these five vulnerabilities being actively exploited? No. None are listed in any KEV catalog, and our source data contains no exploitation reports for any of them.

Which of these five is the most severe? MySQL MCP Server’s CVE-2026-59971, CVSS 10.0 — unauthenticated arbitrary SQL execution against the configured database when the server runs in SSE transport mode.

Does the functype-mcp-server issue require network access to exploit? Per the record, the vulnerable tool requires no authentication in the default stdio transport, so any MCP client — including an AI agent manipulated via a compromised document it read — that can call the tool can trigger it. A non-default network transport mode extends this to unauthenticated network attackers, per the record.

Are the three CKAN MCP Server issues related to each other? They’re three independent findings with different root causes (cache-key collision, regex allowlist bypass, unsanitized error messages), not one bug reported three times — but their shared fix release suggests a single coordinated review turned up all three together.


Data sourced from the GitHub Advisory Database, evaluated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 GitHub Advisory Database

Related intelligence


Analyst tools