Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-85620: Postgres MCP Pro 0.3.0 allows file reading despite restrictions

CVE-2026-85620 · published 23 days ago
Summary

The Postgres MCP Pro version 0.3.0 does not properly check certain functions used in query tables, so an attacker can trick the database into running a file‑reading command. This bypasses the built‑in restricted mode and could expose sensitive files on the server. Update to a version that fixes the check or disable the ability to run such functions until a patch is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
crystaldba postgres-mcp <= 0.3.0
Original advisory text
Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function
Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.
Severity
9.2 Critical
CVSS 3.1: 8.6 (NVD)
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published4 Sep 2026
Updated27 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-85620 · MITRE
Track software like this
Free during beta