A security vulnerability, identified as CVE-2026-85787, has been discovered in AWS Labs' Postgres MCP server. The vulnerability stems from an incomplete keyword denylist in the `mutable_sql_detector.py` script, which allowed SQL commands to bypass read-only configurations. This could enable attackers to mutate data or alter session states, even when the server was intended to be read-only. AWS has released patches, with versions 1.1.7 and later addressing the issue by strengthening the denylist and adding specific pattern blocks. AI
IMPACT Mitigates a specific security risk for users of the AWS Labs Postgres MCP server, preventing unauthorized data mutation.
RANK_REASON Security patch for a specific software package, not a core AI model release.
- aurora
- AWS
- awslabs.postgres-mcp-server
- CVE-2026-85787
- mutable_sql_detector.py
- PostgreSQL
- Python Package Index
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →