To remediate this issue, users should upgrade to version 1.1.7 or later.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 10 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should upgrade to version 1.1.7 or later. | |
| Title | Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server | |
| First Time appeared |
Aws
Aws aws Labs Postgres Mcp Server |
|
| Weaknesses | CWE-184 CWE-78 |
|
| CPEs | cpe:2.3:a:aws:aws_labs_postgres_mcp_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws Labs Postgres Mcp Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-10T13:53:27.245Z
Reserved: 2026-09-09T15:23:09.508Z
Link: CVE-2026-87911
Updated: 2026-09-10T13:53:24.355Z
Status : Deferred
Published: 2026-09-09T20:21:02.017
Modified: 2026-09-10T15:53:23.707
Link: CVE-2026-87911
No data.
OpenCVE Enrichment
Updated: 2026-09-09T21:30:15Z