CVE-2026-59971
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
pip/mysql-mcp-server < 0.4.2
Remediation Resources
Related Vulnerabilities
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
