Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.3.0 is sufficient to resolve this issue. Patch name: 080bef9a96d625ce0dfbde573a08b93497871981. Upgrading the affected component is advised. | |
| Title | designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection | |
| First Time appeared |
Designcomputer
Designcomputer mysql-mcp-server |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:designcomputer:mysql-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Designcomputer
Designcomputer mysql-mcp-server |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-08T16:26:36.609Z
Reserved: 2026-06-07T19:46:50.204Z
Link: CVE-2026-11529
Updated: 2026-06-08T16:26:33.009Z
Status : Deferred
Published: 2026-06-08T16:16:37.650
Modified: 2026-06-09T01:34:33.987
Link: CVE-2026-11529
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:57:04Z