{"id":"CVE-2026-87911","title":"An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a s…","summary":"An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a s…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-78","CWE-184"],"vendor":"AWS","product":"AWS Labs postgres MCP Server","affected":["labs_postgres_mcp_server < 1.1.7"],"published":"2026-09-09","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:53:23.707","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-87911","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-104-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/mcp/security/advisories/GHSA-fph8-pg5w-78fv","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://pypi.org/project/awslabs.postgres-mcp-server/1.1.7/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T13:53:17.650302Z"},"ingestedAt":"2026-09-13T19:02:50.753Z","epss":0.00986,"epssPercentile":0.60939,"slug":"CVE-2026-87911","body":"## Overview\n\nAn OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode.\n\n\n\nTo remediate this issue, users should upgrade to version 1.1.7 or later.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":52.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}