MariaDB MCP Unauthorized Access Vulnerability in SSE Service

Vulnerability

A vulnerability allowing unauthorized access to sensitive information has been identified in MariaDB MCP version 0.1.0. This issue arises because the Server-Sent Events (SSE) service does not validate user authentication, leaving it open to exploitation.

Impact

Exploitation of this vulnerability allows attackers to access sensitive database information without proper authentication.

Reproduction

The vulnerability can be reproduced by running a local server with the SSE transport option enabled. Once the server is active, access can be gained to the SSE endpoint, where sensitive database information can be retrieved.

Added: Sep 10, 2025, 2:21 PM
Updated: Sep 10, 2025, 3:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.