CVE-2026-31841CWE-433

Raw exposure of database statements in Hyperterse MCP search tool

Medium · published March 12, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
7.5
In the wild
Unconfirmed
What it is

Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0, the search tool allows LLMs to search for tools using natural language. While returning results, Hyperterse also returned the raw SQL queries, exposing statements which were supposed to be executed under the hood, and protected from being displayed publicly. This issue has been fixed as of v2.2.0.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00178 · 7.5th percentile
Weakness
CWE-433 · Unparsed Raw Web Content Delivery
Published
2026-03-12T17:03Z
EPSS history
Timeline
  • 12 MAR 17:03Z
    Raw exposure of database statements in Hyperterse MCP search tool
    cvelistv5