SQL injection in agent / MCP tool database query - ATR-2026-00570 (7fabf9b5-cf52-5368-aa04-00a10bed7c4b)
An agent or MCP tool builds a SQL query from unvalidated input, letting an attacker (or prompt injection in retrieved content) inject a tautology, a UNION SELECT to read other tables, or a stacked DROP/DELETE. Generalizes a cluster of agent-app SQLi CVEs.