VYPR

postgres-mcp-server

by Amazon

CVEs (1)

  • CVE-2026-85787MedSep 4, 2026
    risk 0.42cvss 6.5epss

    An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an…