CVE-2026-87911

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should upgrade to version 1.1.7 or later.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 20:21

Updated : 2026-09-10 15:53


NVD link : CVE-2026-87911

Mitre link : CVE-2026-87911

CVE.ORG link : CVE-2026-87911


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-184

Incomplete List of Disallowed Inputs