CVE-2026-48774 Details
Description
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool violates its documented read-only contract for MySQL targets. The tool validates only the full input string with a substring blacklist and first-keyword allowlist, but then executes the entire SQL string on a backend connection created with `CLIENT_MULTI_STATEMENTS`. As a result, a caller can submit a read-only first statement followed by a side-effecting second statement, such as `SELECT 1; RENAME TABLE ...`. The validator accepts the payload because it starts with `SELECT` and because side-effecting MySQL statements such as `RENAME TABLE`, `SET`, `RESET`, `LOCK TABLES`, and `KILL` are not rejected by the blacklist. In a live MCP runtime test, the `/mcp/query` endpoint accepted a `run_sql_readonly` request. The MCP response reported success for the first `SELECT`, and direct backend verification showed that the table had actually been renamed. This violates the endpoint's read-only security contract and lets an MCP caller perform backend writes or administrative SQL, limited by the configured MCP target account's database privileges. Version 3.0.9 contains a fix. Other operator mitigations include: keeping MCP disabled unless required; setting a non-empty `mcp-query_endpoint_auth` token before exposing `/mcp/query`; restricting MCP listener network exposure; configuring MCP backend target credentials as database-level read-only users; and adding temporary MCP query rules to block obvious multi-statement patterns.
A vulnerability exists in ProxySQL versions 3.0.0 through 3.0.8 and 4.0.6 through 4.0.8, where the GenAI/MCP 'run_sql_readonly' tool violates its read-only contract for MySQL targets. The tool executes SQL commands on a backend connection with 'CLIENT_MULTI_STATEMENTS' enabled, allowing the execution of side-effecting statements after a read-only command. This issue was confirmed by renaming a table through the 'run_sql_readonly' tool, demonstrating a breach of the promised read-only functionality. The vulnerability arises because the input validation only checks for substrings and the first keyword of the SQL command, allowing multi-statement payloads to bypass the safeguards. The impact is particularly concerning as it could lead to unauthorized modifications of the database or execution of administrative SQL commands, depending on the privileges of the MCP target account.
Users can update to ProxySQL version 3.0.9 or 4.0.9, where this vulnerability has been fixed. Additionally, it is recommended to keep MCP disabled unless needed, set a non-empty 'mcp-query_endpoint_auth' token before exposing the '/mcp/query' endpoint', restrict MCP listener network exposure, and configure MCP backend target credentials as database-level read-only users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sysown/proxysql/security/advisories/GHSA-7wh6-2vcc-gcm4 | CISA-ADP | ExploitMitigationVendor Advisory |
| https://github.com/sysown/proxysql/commit/e32b7fd50c7c234ea628e392e621e09a2a919e08 | [email protected] | Patch |
| https://github.com/sysown/proxysql/security/advisories/GHSA-7wh6-2vcc-gcm4 | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| proxysql proxysql | >= 4.0.6, < 4.0.9 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |