CVE-2026-85787: postgres-mcp-server SQL Validation Bypass – Update Required
Amazon awslabs postgres-mcp-server versions before 1.1.7 have a sneaky SQL validation bug (CVE-2026-85787) that lets attackers bypass read-only restrictions and modify data they shouldn't touch. The vulnerability lives in the SQL validation component and can be exploited through crafted SQL in user submissions. **Action required**: upgrade your postgres-mcp-server to version 1.1.7 or later immediately if you're running anything older.
source: [aws/security-bulletin]