CVE-2026-5322Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Discloure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-27: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-27: 104-0204-27
Signal classification3 categories
Disclosure
133.3%
Discloure
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-022
Disclosure1Discloure1
2026-04-271
Patch1
Full discourse3 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH Severity: CVE-2026-5322 (CVSS 7.3) SQL injection in AlejandroArciniegas mcp-data-vis MCP Handler. Remotely exploitable, exploit public. Vendor unresponsive. Patch immediately if using this component. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/JYwzi61OQu

    Post summary

    A high‑severity SQL injection vulnerability in the AlecArciniegas mcp-data-vis MCP Handler is disclosed with a clear patch recommendation; no exploit code or active exploitation evidence is provided.

    0000048
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5322 A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the f… https://www.cve.org/CVERecord?id=CVE-2026-5322

    Post summary

    The text announces the discovery of CVE‑2026‑5322 in the AlejandroArciniegas mcp‑data‑vis repository, but provides no further technical or exploit details.

    00000294
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Discloure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5322 - AlejandroArciniegas mcp-data-vis MCP server.js request sql injection Intel Report: https://ift.tt/YRyPi4e

    Post summary

    The message announces CVE‑2026‑5322 as a SQL injection flaw in MCP server.js, providing only a threat notice and no PoC, exploit code, or patch information.

    0000031
    281 followersView on X

Explore more