CVE-2025-66335 affects Apache Doris MCP Server versions prior to 0.6.1 and involves an improper neutralization flaw in query context handling that permits attackers to execute unintended SQL statements and circumvent query validation and access controls through the MCP query execution interface. The vulnerability has been patched in version 0.6.1 and later releases. The vulnerability carries a CVSS score of 5.3 (Medium severity) with a network attack vector and low complexity, meaning it can be exploited remotely without authentication or user interaction. However, the impact is limited to confidentiality, with no disruption to integrity or availability. The EPSS score of 0.000790 indicates minimal real-world exploitation probability. Regarding exploitation status, there is no indication of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities list and has an inactive hot list status. No publicly available exploit code has been widely distributed. Given the moderate risk profile and low exploitation metrics, this represents a manageable vulnerability that should be addressed through standard patch management procedures, with priority given to systems handling sensitive data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, < 0.6.1CPE matchmatch criteria | cpe:2.3:a:apache:doris_mcp_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.