Information Disclosure Vulnerability in MariaDB MCP by MariaDB
CVE-2025-56404

7.5HIGH

Key Information:

Vendor

MariaDB

Vendor
CVE Published:
10 September 2025

What is CVE-2025-56404?

A vulnerability in MariaDB MCP version 0.1.0 has been identified, where the SSE service is improperly secured, leading to potential unauthorized access to sensitive information. This issue arises due to insufficient user validation mechanisms, allowing attackers to exploit the service for data extraction.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-56404 : Information Disclosure Vulnerability in MariaDB MCP by MariaDB