Tools AI Risk Radar ai-incident-0003
Incident record
AWS's own Postgres MCP server let read-only sessions write past their scope
- Severity
- High
- Status
- Patched
- Type
- Agent Hijack
- Target
- awslabs.postgres-mcp-server before 1.1.7
- Actor
- researcher
- CVE
- CVE-2026-85787
What happened
An unauthenticated actor could place crafted SQL in content later submitted during an authenticated user’s interaction. An incomplete input denylist let that SQL bypass the Postgres MCP server’s intended read-only scope. AWS fixed the issue in 1.1.7 and published its own bulletin.
Sources
- AWS security bulletin 2026-101aws.amazon.com/security/security-bulletins/2026-101-aws/
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026