Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-66335

22
FAUCET Score

CVE-2025-66335 affects Apache Doris MCP Server versions prior to 0.6.1 and involves an improper neutralization flaw in query context handling that permits attackers to execute unintended SQL statements and circumvent query validation and access controls through the MCP query execution interface. The vulnerability has been patched in version 0.6.1 and later releases. The vulnerability carries a CVSS score of 5.3 (Medium severity) with a network attack vector and low complexity, meaning it can be exploited remotely without authentication or user interaction. However, the impact is limited to confidentiality, with no disruption to integrity or availability. The EPSS score of 0.000790 indicates minimal real-world exploitation probability. Regarding exploitation status, there is no indication of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities list and has an inactive hot list status. No publicly available exploit code has been widely distributed. Given the moderate risk profile and low exploitation metrics, this represents a manageable vulnerability that should be addressed through standard patch management procedures, with priority given to systems handling sensitive data.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.1.0, < 0.6.1CPE matchmatch criteria
cpe:2.3:a:apache:doris_mcp_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.66%
Probability of exploitation in next 30 days
EPSS Percentile
47.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0066 is in the 30th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: doris-mcp-serverFixed in: 0.6.1
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

pipGHSA-qhfq-gvvc-5q6qmedium

Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization

Apr 20, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10945.html

CVE-2025-66335: Apache Doris MCP Server: MCP SQL inject

Apr 17, 2026

References

openwall.com / lists/oss-security/2026/04/17/4
Mailing List
lists.apache.org / thread/odp0fyyst8kxm7hhm9z4d1snh1y4hjpy
Vendor Advisory