MCPA-2026-0024
mediumoverprivilegedCVSS 4.3
Dynatrace MCP Server DQL injection via parameters not documented as DQL (GHSA-pqh8-p93p-2rx7)
@dynatrace-oss/dynatrace-mcp-server before 2.1.1 interpolates caller-supplied parameters typed as identifiers or constrained shorthand (timeframes, Kubernetes UIDs) directly into DQL query strings in several read tools. Injected DQL pipeline stages and // comments bypass the tools' documented field-scope, time-window, and display caps — including the readOnlyHint: true contract MCP clients may use for auto-approval. Fixed in 2.1.1 (PR #562).
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | @dynatrace-oss/dynatrace-mcp-server | >= 0, < 2.1.1 |
Identifiers
GHSA-pqh8-p93p-2rx7CWE-89
References
- advisory https://github.com/advisories/GHSA-pqh8-p93p-2rx7
- advisory https://github.com/dynatrace-oss/dynatrace-mcp/security/advisories/GHSA-pqh8-p93p-2rx7
- fix https://github.com/dynatrace-oss/dynatrace-mcp/pull/562
- fix https://github.com/dynatrace-oss/dynatrace-mcp/commit/15d3546c0618ffbaeaeca477337e08e92f2151bc
Timeline
- Published: 2026-07-31