The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result, the server is susceptible to abuse and attacks on affected database systems such as PostgreSQL, and potentially others that expose elevated functionalities. These attacks may lead to denial of service and other unexpected behaviors.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Executeautomation
Executeautomation mcp-database-server |
|
Vendors & Products |
Executeautomation
Executeautomation mcp-database-server |
Tue, 16 Sep 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 16 Sep 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result, the server is susceptible to abuse and attacks on affected database systems such as PostgreSQL, and potentially others that expose elevated functionalities. These attacks may lead to denial of service and other unexpected behaviors. | |
Title | @executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-16T14:18:48.881Z
Updated: 2025-09-16T18:19:09.072Z
Reserved: 2025-09-12T12:36:24.635Z
Link: CVE-2025-59333

Updated: 2025-09-16T18:18:56.983Z

Status : Awaiting Analysis
Published: 2025-09-16T15:15:46.450
Modified: 2025-09-17T14:18:55.093
Link: CVE-2025-59333

No data.