YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0003

Incident record

AWS's own Postgres MCP server let read-only sessions write past their scope

Severity
High
Status
Patched
Type
Agent Hijack
Target
awslabs.postgres-mcp-server before 1.1.7
Actor
researcher
CVE
CVE-2026-85787

What happened

An unauthenticated actor could place crafted SQL in content later submitted during an authenticated user’s interaction. An incomplete input denylist let that SQL bypass the Postgres MCP server’s intended read-only scope. AWS fixed the issue in 1.1.7 and published its own bulletin.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026