YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0005

Incident record

Postgres MCP Pro's restricted mode had a hole a FROM clause fits through

Severity
Critical
Status
Proof-of-concept
Type
Data Leak
Target
crystaldba/postgres-mcp 0.3.0
Actor
researcher
CVE
CVE-2026-85620

What happened

Restricted-mode function validation checked the target list but missed functions in a FROM clause. With a database connection role holding superuser or pg_read_server_files privileges, this could permit arbitrary server-file reads despite restricted mode. The CVE records CVSS 4.0 9.2. The cited issue and fix pull request remained open at the 10 September check; these sources did not establish a released fix.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026