CVE-2026-85787: An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server
An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server.
To remediate this issue, users should upgrade to version 1.1.7 or above.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon awslabs postgres-mcp-serverto a version that resolves this vulnerability.Fixed in 1.1.7
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An unauthenticated actor must be able to place crafted SQL in content that is submitted when an authenticated user interacts with the MCP server. The issue relies on that authenticated user interaction to reach the server.
What is the impact if exploitation succeeds?
Crafted SQL may allow modification of data beyond the intended read-only scope. The provided severity vector indicates integrity impact, with no stated confidentiality or availability impact.
Which versions should be remediated?
postgres-mcp-server versions before 1.1.7 are affected. Upgrade to version 1.1.7 or later.