← Back to search Server uses network capabilities via: httpx, socket, urllib Server uses filesystem capabilities via: open(), os, pathlib, shutil, tempfile Server uses shell capabilities via: subprocess Server uses database capabilities via: sqlalchemy Server uses env_vars capabilities via: os.environ, os.getenv()
DB Connect MCP
Multi-database MCP server for PostgreSQL, MySQL, and ClickHouse
? Not scanned yet
Versions
0.3.1latestfirst seen Jun 5, 2026
Tools 0
No tools indexed yet.
Permissions 5
network medium filesystem low shell high database medium env_vars low Scan Findings 50
high
Hardcoded OAuth client secret in yugui923-db-connect-mcp-41f1a60/src/db_connect_mcp/auth/jwt_verifier.py
info
Sandbox failed to start for behavioral verification
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (GHSA-3qhf-m339-9g5v)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (GHSA-9h52-p55h-vw2f)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (GHSA-j975-95f5-7wqh)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (GHSA-jpw9-pfvf-9f58)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (GHSA-vj7q-gjh5-988w)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (PYSEC-2026-1616)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (PYSEC-2026-1617)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (PYSEC-2026-1618)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (PYSEC-2026-3482)
medium
Vulnerable dependency: mcp@2.0.0,<3.0.0 (PYSEC-2026-3483)
medium
Vulnerable dependency: pydantic@2.13.4,<3.0.0 (GHSA-5jqp-qgf6-3pvh)
medium
Vulnerable dependency: pydantic@2.13.4,<3.0.0 (GHSA-mr82-8j83-vxmv)
medium
Vulnerable dependency: pydantic@2.13.4,<3.0.0 (PYSEC-2021-47)
medium
Vulnerable dependency: pydantic@2.13.4,<3.0.0 (PYSEC-2026-1812)
medium
Vulnerable dependency: paramiko@5.0.0,<6.0.0 (GHSA-232r-66cg-79px)
medium
Vulnerable dependency: paramiko@5.0.0,<6.0.0 (GHSA-r374-rxx8-8654)
medium
Vulnerable dependency: paramiko@5.0.0,<6.0.0 (GHSA-wqmm-q65g-2hqr)
medium
Vulnerable dependency: paramiko@5.0.0,<6.0.0 (PYSEC-2008-8)
medium
Vulnerable dependency: paramiko@5.0.0,<6.0.0 (PYSEC-2018-19)
medium
Vulnerable dependency: paramiko@5.0.0,<6.0.0 (PYSEC-2022-166)
medium
Vulnerable dependency: paramiko@5.0.0,<6.0.0 (PYSEC-2026-2858)
medium
Vulnerable dependency: cryptography@49.0.0 (GHSA-g6cj-pr64-35w5)
medium
Vulnerable dependency: cryptography@49.0.0 (PYSEC-2026-3552)
high
Long hex escape sequence in yugui923-db-connect-mcp-41f1a60/tests/unit/test_tunnel.py:1119
info
pyproject.toml metadata
info
Transport: stdio
info
Required env vars (31)
high
High-risk OAuth scope: admin
info
Sandbox failed to start for output poisoning scan
medium
Permission: network access detected
low
Permission: filesystem access detected
high
Permission: shell access detected
medium
Permission: database access detected
low
Permission: env_vars access detected
info
No dependency files found for SBOM generation
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/CLAUDE.md
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/claude_desktop_config.example.json
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/README.md
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/.devcontainer/devcontainer.json
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/src/db_connect_mcp/models/config.py
high
Hardcoded Password found in yugui923-db-connect-mcp-41f1a60/src/db_connect_mcp/models/config.py
critical
RSA Private Key found in yugui923-db-connect-mcp-41f1a60/src/db_connect_mcp/core/tunnel.py
critical
EC Private Key found in yugui923-db-connect-mcp-41f1a60/src/db_connect_mcp/core/tunnel.py
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/.github/workflows/ci.yml
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/docs/guides/DEVELOPMENT.md
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/docs/guides/DOCKER.md
critical
Database URL with Password found in yugui923-db-connect-mcp-41f1a60/docs/guides/SSH_TUNNEL.md
medium
No build provenance detected (SLSA L0)