Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @executeautomation/database-server
  4. ›
  5. CVE-2025-59333

CVE-2025-59333: @executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode

September 16, 2025

The MCP Server provided by ExecuteAutomation at https://github.com/executeautomation/mcp-database-server provides an MCP interface for agentic workflows to interact with different kinds of database servers such as PostgreSQL database. However, the mcp-database-server MCP Server distributed via the npm package @executeautomation/database-server fails to implement proper security control that properly enforce a “read-only” mode and as such it is vulnerable to abuse and attacks on the affected database servers such as PostgreSQL (and potentially other db servers that expose elevated functionalities) and which may result in denial of service and other unexpected behavior.

This MCP Server is also publicly published in the npm registry: https://www.npmjs.com/package/@executeautomation/database-server

References

  • github.com/advisories/GHSA-65hm-pwj5-73pw
  • github.com/executeautomation/mcp-database-server
  • github.com/executeautomation/mcp-database-server/security/advisories/GHSA-65hm-pwj5-73pw
  • nvd.nist.gov/vuln/detail/CVE-2025-59333

Code Behaviors & Features

Detect and mitigate CVE-2025-59333 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1.1.0

Solution

Unfortunately, there is no solution available yet.

Impact 8.1 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-284: Improper Access Control

Source file

npm/@executeautomation/database-server/CVE-2025-59333.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 08 Oct 2025 00:20:30 +0000.