Tools AI Risk Radar ai-incident-0005
Incident record
Postgres MCP Pro's restricted mode had a hole a FROM clause fits through
- Severity
- Critical
- Status
- Proof-of-concept
- Type
- Data Leak
- Target
- crystaldba/postgres-mcp 0.3.0
- Actor
- researcher
- CVE
- CVE-2026-85620
What happened
Restricted-mode function validation checked the target list but missed functions in a FROM clause. With a database connection role holding superuser or pg_read_server_files privileges, this could permit arbitrary server-file reads despite restricted mode. The CVE records CVSS 4.0 9.2. The cited issue and fix pull request remained open at the 10 September check; these sources did not establish a released fix.
Sources
- crystaldba/postgres-mcp issue 178github.com/crystaldba/postgres-mcp/issues/178
- NVD, CVE-2026-85620nvd.nist.gov/vuln/detail/CVE-2026-85620
- Proposed Postgres MCP fix, PR 200github.com/crystaldba/postgres-mcp/pull/200
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026