CVE-2026-87911
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should upgrade to version 1.1.7 or later.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- CWE
- CWE-78, CWE-184
- Published
- 2026-09-09
- Last modified
- 2026-09-10
Affected products
- AWS AWS Labs postgres MCP Server
Weakness type
Related vulnerabilities
- CVE-2026-17176 — OS command injection Vulnerability in Deco BE11000
- CVE-2026-78569 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-78575 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-79724 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-81550 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82095 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82098 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82099 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software