Skip to content

Hide Navigation Hide TOC

Apache Doris MCP Server SQL Injection (CVE-2025-66335) - ATR-2026-00532 (14c23f83-5430-5a6c-b0a7-fdfe20d89a6e)

Detects CVE-2025-66335: Apache Doris MCP server passes user-supplied SQL fragments directly to query execution without sanitisation. An attacker can inject arbitrary SQL via MCP tool call arguments to read, modify, or destroy database contents. Detection covers (a) tool call arguments containing SQL injection payloads targeting Doris MCP tool names, (b) MCP configs pointing at Doris endpoints, (c) content describing the injection surface. CWE-89 (SQL Injection).

Cluster A Galaxy A Cluster B Galaxy B Level
Unix Shell - T1059.004 (a9d4b653-6915-42af-98b2-5758c4ceee56) Attack Pattern Apache Doris MCP Server SQL Injection (CVE-2025-66335) - ATR-2026-00532 (14c23f83-5430-5a6c-b0a7-fdfe20d89a6e) Agent Threat Rules 1
Exploit Public-Facing Application (47d73872-5336-44f7-81e3-d30bc7e039dd) MITRE ATLAS Attack Pattern Apache Doris MCP Server SQL Injection (CVE-2025-66335) - ATR-2026-00532 (14c23f83-5430-5a6c-b0a7-fdfe20d89a6e) Agent Threat Rules 1
Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern Apache Doris MCP Server SQL Injection (CVE-2025-66335) - ATR-2026-00532 (14c23f83-5430-5a6c-b0a7-fdfe20d89a6e) Agent Threat Rules 1
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Unix Shell - T1059.004 (a9d4b653-6915-42af-98b2-5758c4ceee56) Attack Pattern 2