An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode.



To remediate this issue, users should upgrade to version 1.1.7 or later.

Project Subscriptions

Vendors Products
Aws Labs Postgres Mcp Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 09 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode. To remediate this issue, users should upgrade to version 1.1.7 or later.
Title Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server
First Time appeared Aws
Aws aws Labs Postgres Mcp Server
Weaknesses CWE-184
CWE-78
CPEs cpe:2.3:a:aws:aws_labs_postgres_mcp_server:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws aws Labs Postgres Mcp Server
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-09T19:37:17.985Z

Reserved: 2026-09-09T15:23:09.508Z

Link: CVE-2026-87911

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T20:21:02.017

Modified: 2026-09-09T20:21:02.017

Link: CVE-2026-87911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses