Researchers identified SQL injection and improper-access-control weaknesses in Model Context Protocol (MCP) database servers that label interfaces as read-only by checking only whether submitted SQL begins with SELECT. In PostgreSQL, SELECT can call functions with side effects or administrative privileges; where multi-statement queries are allowed, attackers may also append additional commands. CVE-2025-59333 affects ExecuteAutomation's @executeautomation/database-server npm package and is rated CVSS 8.1.
An authenticated low-privilege user able to submit MCP queries could modify data through stored functions, retrieve data beyond intended scope under the service account's permissions, terminate database backends, or trigger expensive queries for denial of service. Organizations should not rely on SQL prefix filtering: enforce read-only database roles and transactions, restrict connections to allowlisted tables and functions, require single statements, use parameterized queries, and apply least-privilege permissions to MCP service accounts.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
An improper-access-control vulnerability in ExecuteAutomation's MCP Database Server npm package (@executeautomation/database-server) allows queries based solely on whether they begin with SELECT. In PostgreSQL, an authenticated low-privilege attacker could invoke side-effecting functions to alter data, terminate database backends for denial of service, or access data permitted to the server's database account; the issue is rated CVSS 8.1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
nodejs-security.com
Open sourcenodejs-security.com
Open sourcesecuritylabs.datadoghq.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.