CVE-2026-59971 | MySQL MCP Server up to 0.4.1 SSE Transport server.py cursor.execute Query dns rebinding
A vulnerability identified as critical has been detected in MySQL MCP Server up to 0.4.1. The affected element is the function cursor.execute of the file src/mysql_mcp_server/server.py of the component SSE Transport. The manipulation of the argument Query leads to reliance on reverse dns resolution.
This vulnerability is listed as CVE-2026-59971. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More