Improper Neutralization Vulnerability in Apache Doris MCP Server
CVE-2025-66335

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
20 April 2026

What is CVE-2025-66335?

Apache Doris MCP Server versions prior to 0.6.1 contain a vulnerability that stems from improper handling of query contexts. This flaw allows for the execution of unintended SQL statements, potentially bypassing intended query validations and access restrictions within the MCP query execution interface. Users are advised to upgrade to version 0.6.1 or later to mitigate this security risk.

Affected Version(s)

Apache Doris MCP Server 0.1.0 < 0.6.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tomer Peled, Senior Security Researcher at Akamai
.