The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result, the server is susceptible to abuse and attacks on affected database systems such as PostgreSQL, and potentially others that expose elevated functionalities. These attacks may lead to denial of service and other unexpected behaviors.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Executeautomation mcp Database Server
|
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:executeautomation:mcp_database_server:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Executeautomation mcp Database Server
|
Wed, 17 Sep 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Executeautomation
Executeautomation mcp-database-server |
|
Vendors & Products |
Executeautomation
Executeautomation mcp-database-server |
Tue, 16 Sep 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 16 Sep 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects only the npm distribution; other distributions are not impacted. As a result, the server is susceptible to abuse and attacks on affected database systems such as PostgreSQL, and potentially others that expose elevated functionalities. These attacks may lead to denial of service and other unexpected behaviors. | |
Title | @executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-16T18:19:09.072Z
Reserved: 2025-09-12T12:36:24.635Z
Link: CVE-2025-59333

Updated: 2025-09-16T18:18:56.983Z

Status : Analyzed
Published: 2025-09-16T15:15:46.450
Modified: 2025-10-08T19:18:04.110
Link: CVE-2025-59333

No data.

Updated: 2025-09-17T10:52:12Z