CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope
Imported from official source
Bulletin ID: 2026-101-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 13:00 PM PDT Description: We have identified CVE-2026-85787, an incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server. Impacted versions: any pypi package version < 1.1.7 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
This version
- Version
- 2 of 2
- Recorded
- September 17, 2026 21:30
- Change
- Imported change
- Content hash
556d4afeea83cb741fd9d79ef6c649cf- All versions
- Revision history