CVE-2026-33980 | pab1it0 adx-mcp-server up to 1.1.0 table_name data query logic injection (GHSA-vphc-468g-8rfp)
A vulnerability labeled as critical has been found in pab1it0 adx-mcp-server up to 1.1.0. This issue affects the function get_table_schema/sample_table_data/get_table_details. Executing a manipulation of the argument table_name can lead to improper neutralization of special elements in data query logic.
This vulnerability appears as CVE-2026-33980. The attack may be performed from remote. There is no available exploit.
It is advisable to implement a patch to correct this issue.