{"id":"CVE-2026-61788","summary":"@bytebase/dbhub's read-only mode does not prevent database writes","details":"DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to set PostgreSQL `default_transaction_read_only=on` (and open SQLite in `readOnly` mode), but that code is gated on a config value that is never populated, so it never runs. The only thing left enforcing read-only is a classifier that inspects the first keyword of each statement. Any `SELECT` that writes or has side effects through a function call passes it. With an ordinary role this allows sequence tampering; with a privileged role it allows writing arbitrary files on the server (`lo_export`), reading arbitrary host files (`pg_read_file`), and remote code execution (`dblink` + `COPY ... TO PROGRAM`). The HTTP transport is unauthenticated and binds to `0.0.0.0` by default, so this is reachable by any network caller of `/mcp`. Version 0.22.6 patches the issue.","aliases":["GHSA-mwwr-p57h-56pf"],"modified":"2026-09-25T03:48:35.029462407Z","published":"2026-09-24T17:37:40.409Z","database_specific":{"cwe_ids":["CWE-184","CWE-636","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61788.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61788.json"},{"type":"ADVISORY","url":"https://github.com/bytebase/dbhub/security/advisories/GHSA-mwwr-p57h-56pf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61788"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bytebase/dbhub","events":[{"introduced":"0"},{"fixed":"6647caa4bfc6c197731d88ee0ebd7baeb846d1c0"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.22.6"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61788.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}