CVE-2026-85620
9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Summary
Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| crystaldba | postgres-mcp | 0 <= 0.3.0 | affected |
Weaknesses
- CWE-863: Incorrect Authorization
References
- https://github.com/crystaldba/postgres-mcp/issues/178
- https://github.com/crystaldba/postgres-mcp
- https://github.com/crystaldba/postgres-mcp/blob/v0.3.0/src/postgres_mcp/sql/safe_sql.py
- https://www.vulncheck.com/advisories/postgres-mcp-pro-0.3.0-restricted-mode-bypass-via-from-clause-function
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.