CVE-2026-85787
Received Received - Intake

SQL Injection in Amazon awslabs postgres-mcp-server

Vulnerability report for CVE-2026-85787, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: AMZN

Description

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server. To remediate this issue, users should upgrade to version 1.1.7 or above.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
awslabs postgres-mcp-server 1.1.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an incomplete input validation in the SQL component of Amazon's awslabs postgres-mcp-server before version 1.1.7. An unauthenticated attacker could exploit this by injecting crafted SQL into submitted content, potentially allowing them to modify data beyond the intended read-only scope when an authenticated user interacts with the MCP server.

Detection Guidance

This vulnerability involves crafted SQL input in the awslabs postgres-mcp-server before version 1.1.7. Detection requires checking server versions and monitoring for unusual SQL queries. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow unauthorized data modifications, potentially leading to data corruption, loss of integrity, or unintended exposure of sensitive information. Attackers might alter records or insert malicious SQL commands without proper authentication.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized data modifications or access, which may breach integrity and confidentiality principles in GDPR and HIPAA. Organizations using affected versions risk non-compliance penalties due to insufficient data protection controls.

Mitigation Strategies

Upgrade the awslabs postgres-mcp-server to version 1.1.7 or higher to address the incomplete SQL validation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85787. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart