Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-85620: Postgres MCP Pro 0.3.0 allows file reading despite restrictions
CVE-2026-85620 · published 23 days ago
Summary
The Postgres MCP Pro version 0.3.0 does not properly check certain functions used in query tables, so an attacker can trick the database into running a file‑reading command. This bypasses the built‑in restricted mode and could expose sensitive files on the server. Update to a version that fixes the check or disable the ability to run such functions until a patch is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| crystaldba | postgres-mcp | <= 0.3.0 |
Original advisory text
Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function
Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.
References
- https://www.vulncheck.com/advisories/postgres-mcp-pro-0.3.0-restricted-mode-bypa...
- https://github.com/crystaldba/postgres-mcp/issues/178
- https://github.com/crystaldba/postgres-mcp
- https://github.com/crystaldba/postgres-mcp/blob/v0.3.0/src/postgres_mcp/sql/safe...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85620... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-85620 Vendor Advisory
Severity
9.2
Critical
CVSS 3.1: 8.6 (NVD)
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published4 Sep 2026
Updated27 Sep 2026
First seen4 Sep 2026
Track software like this
Free during beta