{"api_version":"1","generated_at":"2026-06-22T18:11:49+00:00","cve":"CVE-2025-66336","urls":{"html":"https://cve.report/CVE-2025-66336","api":"https://cve.report/api/cve/CVE-2025-66336.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-66336","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-66336"},"summary":{"title":"Apache Doris MCP Server: SQL injection leading the authentication bypass","description":"Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.\n\nAffected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-06-22 08:16:36","updated_at":"2026-06-22 16:40:18"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/06/22/1","name":"http://www.openwall.com/lists/oss-security/2026/06/22/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.apache.org/thread/4l4v3m7ofwrgp4s4s98pjb5l03fcrzo2","name":"https://lists.apache.org/thread/4l4v3m7ofwrgp4s4s98pjb5l03fcrzo2","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-66336","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66336","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Doris MCP Server","version":"affected 0.1.0 0.6.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"cherno.x.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-06-22T07:58:10.548Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/06/22/1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"collectionURL":"https://pypi.python.org","defaultStatus":"unaffected","packageName":"doris-mcp-server","product":"Apache Doris MCP Server","vendor":"Apache Software Foundation","versions":[{"lessThan":"0.6.1","status":"affected","version":"0.1.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"cherno.x."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.<br><br>Affected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue."}],"value":"Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.\n\nAffected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue."}],"metrics":[{"other":{"content":{"text":"important"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-22T06:55:17.988Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/4l4v3m7ofwrgp4s4s98pjb5l03fcrzo2"}],"source":{"discovery":"UNKNOWN"},"title":"Apache Doris MCP Server: SQL injection leading the authentication bypass","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2025-66336","datePublished":"2026-06-22T06:55:17.988Z","dateReserved":"2025-11-27T03:24:32.530Z","dateUpdated":"2026-06-22T07:58:10.548Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-22 08:16:36","lastModifiedDate":"2026-06-22 16:40:18","problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"66336","Ordinal":"1","Title":"Apache Doris MCP Server: SQL injection leading the authenticatio","CVE":"CVE-2025-66336","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"66336","Ordinal":"1","NoteData":"Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.\n\nAffected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue.","Type":"Description","Title":"Apache Doris MCP Server: SQL injection leading the authenticatio"}]}}}