npm package report

Is @executeautomation/database-server safe?

1 known vulnerability, worst severity HIGH.

cvss
8.1

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-65hm-pwj5-73pw, the advisory selected below

// advisories

GHSA-65hm-pwj5-73pw

HIGHCVE-2025-59333

The MCP Server provided by ExecuteAutomation at https://github.com/executeautomation/mcp-database-server provides an MCP interface for agentic workflows to interact with different kinds of database servers such as PostgreSQL database. However, the mcp-database-server MCP Server distributed via the npm package @executeautomation/database-server fails to implement proper security control that proper

Affected
<= 1.1.0
Fixed in
not stated
Weakness
CWE-284
Published
2025-09-16
Source
github

GHSANVDMITREreference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:32 UTC. The most recent advisory here was published 2025-09-16. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @executeautomation/database-server safe? npm package security report | CyberXYZ