An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server.
To remediate this issue, users should upgrade to version 1.1.7 or above.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 21:17
Updated : 2026-09-08 16:18
NVD link : CVE-2026-85787
Mitre link : CVE-2026-85787
CVE.ORG link : CVE-2026-85787
JSON object : View
Products Affected
No product.
CWE
CWE-184
Incomplete List of Disallowed Inputs
