
SQL Injection and Bypassing "Read-Only" Mode in Xata's MCP Server
The Model Context Protocol (MCP) Server by Xata had a critical vulnerability that allows SQL injection attacks, bypassing its "read-only" mode. This article explores the flaw, its exploitation, and mitigation strategies.




