GHSA-pqh8-p93p-2rx7: @dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
A DQL injection vulnerability in several read tools lets a caller bypass the tools’ documented field-scope, time-window, and display caps by injecting DQL pipeline stages through parameters typed as identifiers.
References
- github.com/advisories/GHSA-pqh8-p93p-2rx7
- github.com/dynatrace-oss/dynatrace-mcp/commit/15d3546c0618ffbaeaeca477337e08e92f2151bc
- github.com/dynatrace-oss/dynatrace-mcp/pull/562
- github.com/dynatrace-oss/dynatrace-mcp/releases/tag/v2.1.1
- github.com/dynatrace-oss/dynatrace-mcp/security/advisories/GHSA-pqh8-p93p-2rx7
Code Behaviors & Features
Detect and mitigate GHSA-pqh8-p93p-2rx7 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →