Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-85788 - Issue with awslabs mysql-mcp-server

Amazon Web Services Version 1 original

Imported from official source

Bulletin ID: 2026-103-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/09/2026 09:30 AM PDT Description: We identified an issue in awslabs.mysql-mcp-server (an open-source, self-hosted Model Context Protocol server distributed via github.com/awslabs/mcp and PyPI). In affected versions, under certain conditions the read-only enforcement could be circumvented via SQL inline comments, allowing a statement to run that the read-only check was expected to block. The read-only mode provided by the server is a best-effort safeguard and is not a substitute for correct...

This version

Version
1 of 2
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
b85a247c897e66c8c8c5c2ad8dbd4e3b
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.