---
id: CVE-2026-85787
title: >-
  An incomplete list of disallowed inputs in the SQL validation component in
  Amazon awslabs postgres-mcp-server before  version 1.1.7 might allow an
  unauthenticated actor to modify data beyond the read-only scope by placing
  crafted SQL int…
summary: >-
  An incomplete list of disallowed inputs in the SQL validation component in
  Amazon awslabs postgres-mcp-server before  version 1.1.7 might allow an
  unauthenticated actor to modify data beyond the read-only scope by placing
  crafted SQL int…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-184
vendor: Amazon
product: postgres-mcp-server
affected:
  - postgres-mcp-server < 1.1.7
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T16:18:19.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85787'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-101-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://pypi.org/project/awslabs.postgres-mcp-server/1.1.7/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T15:52:34.756750Z'
epss: 0.00342
epssPercentile: 0.25012
ingestedAt: '2026-09-08T15:33:26.964Z'
---

## Overview

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before  version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server.



To remediate this issue, users should upgrade to version 1.1.7 or above.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
