5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether doris-mcp-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.1
CVE-2025-66336
Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path
MEDIUM 5.3
CVE-2025-66335
Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
MEDIUM 5.3
CVE-2025-66335
Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
UNKNOWN
CVE-2025-58337
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
UNKNOWN
CVE-2025-58337
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes