CVE-2026-87911
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1
CVSS
9.6
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 9 sept 2026 · Última mod.: 10 sept 2026 · CWE-78 · CWE-184
Sin historial EPSS suficiente todavía.
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should upgrade to version 1.1.7 or later.