MEDIUM
dubydu
CVE published 2026-04-28
CVE-2026-7206
A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. Performing a manipulation of the argument output_filename results in sql injection. Remote exploitation of the attack is possible. This issue has a CVSS score of 5.5 and is considered Medium severity. Users should apply the patch a5580cb992f4f6c308c9ffe6442b2 [truncated]