An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode.
To remediate this issue, users should upgrade to version 1.1.7 or later.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should upgrade to version 1.1.7 or later. | |
| Title | Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server | |
| First Time appeared |
Aws
Aws aws Labs Postgres Mcp Server |
|
| Weaknesses | CWE-184 CWE-78 |
|
| CPEs | cpe:2.3:a:aws:aws_labs_postgres_mcp_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws Labs Postgres Mcp Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published: 2026-09-09T19:35:46.136Z
Updated: 2026-09-09T19:37:17.985Z
Reserved: 2026-09-09T15:23:09.508Z
Link: CVE-2026-87911
No data.
Status : Received
Published: 2026-09-09T20:21:02.017
Modified: 2026-09-09T20:21:02.017
Link: CVE-2026-87911
No data.