{"id":"CVE-2026-85788","title":"Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via …","summary":"Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via …","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-184"],"vendor":"AWS","product":"AWS Labs MySQL MCP Server","affected":["labs_mysql_mcp_server <= 1.0.21"],"published":"2026-09-09","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:13:26.720","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85788","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-103-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/mcp/releases?page=2#release-2026.07.20260702161703","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/mcp/security/advisories/GHSA-x25m-ph3m-3r9q","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-09T18:59:50.569749Z"},"ingestedAt":"2026-09-13T19:03:46.659Z","epss":0.00184,"epssPercentile":0.07199,"slug":"CVE-2026-85788","body":"## Overview\n\nIncomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace.\n\n\n\nTo remediate this issue, users should upgrade to version 1.0.23.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}