SQL Injection Vulnerability in Amazon Web Services MySQL Management Component
CVE-2026-85788

5.7MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
9 September 2026

What is CVE-2026-85788?

The mutable SQL detector component in Amazon's mysql-mcp-server contains insufficient validation of disallowed inputs, potentially enabling context-dependent actors to circumvent read-only restrictions. This loophole allows attackers to exploit SQL inline comments, bypassing regex treatment as whitespace and reaching sensitive file-read and file-write SQL sinks. For users of the mysql-mcp-server, it is crucial to upgrade to version 1.0.23 to safeguard against these vulnerabilities.

Affected Version(s)

AWS Labs MySQL MCP Server 0 <= 1.0.21

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.