Azure-Samples / Azure-Samples/SQL-AI-samples

[Security] SQL Injection Vulnerability in ListTableTool.ts (MssqlMcp/Node/src/tools)

Offen
#92 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
HTML
Sterne
331
Forks
208
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

## Summary
The `ListTableTool` class in the Node.js MCP sample is vulnerable to SQL injection attacks due to unsanitized user input being directly interpolated into a dynamic SQL query. This affects the `run()` method when filtering by schemas via the `parameters` array.

**Affected File:** [MssqlMcp/Node/src/tools/ListTableTool.ts](https://github.com/Azure-Samples/SQL-AI-samples/blob/main/MssqlMcp/Node/src/tools/ListTableTool.ts)

## Steps to Reproduce
1. Instantiate the `ListTableTool` and call `run()` with malicious input:
```json
{
"parameters": ["dbo'; SELECT name FROM sys.databases --"]
}

query becomes:
`SELECT TABLE_SCHEMA + '.' + TABLE_NAME FROM INFORMATION_SCHEMA.TABLES
WHERE TABLE_TYPE = 'BASE TABLE'
AND TABLE_SCHEMA IN ('dbo'; SELECT name FROM sys.databases --')
ORDER BY TABLE_SCHEMA, TABLE_NAME`

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.