UNKNOWN PyPI

Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode

GHSA-m35w-xx8c-6xc7 · CVE-2025-58337 · PYSEC-2026-1315

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions.

Impact:

Bypasses read-only mode; attackers with read-only access may perform unauthorized modifications.

Recommended action for operators: Upgrade to version 0.6.0 as soon as possible (this release contains the fix).

Ready to move

Start Securing

Free, no credit card | First findings in minutes