Postgres MCP Pro Bypass: AI Database Security Flaw Exposed

3h ago·0:00 listen·Source: forkast.news

Summary

A critical vulnerability, CVE-2026-85620, has been discovered in Postgres MCP Pro's restricted mode. This bypasses the security designed to protect PostgreSQL databases from AI agents. The restricted mode was meant to allow safe, read-only interactions and validate SQL commands. However, a "syntactic trick" lets attackers bypass these controls. This flaw, reported by George Chen, has a CVSS v4.0 score of 9.2. It allows a function to be placed in a FROM clause, which the validator permits without checking its name. For example, SELECT * FROM pg_read_file('/etc/passwd') can execute, allowing access to file contents. This means an attacker can read arbitrary files on the PostgreSQL server, including credentials and system configurations. The attack doesn't need authentication to the restriction logic itself. All versions through 0.3.0 are affected, and a fix is currently under review. This vulnerability highlights a growing concern about security in the rapidly expanding AI infrastructure ecosystem.

Read the full article on forkast.news

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening