Story thread · 2 reports / 1 sources

Postgres MCP Pro’s Safe Mode Was Supposed to Block Dangerous SQL. A Parser Flaw Bypasses It Entirely.

forkast.news · 10d

Restricted mode in Postgres MCP Pro was designed as the safe configuration for exposing a PostgreSQL database to an AI agent. It limits operations to read-only transactions and validates incoming SQL against an allowlist. CVE-2026-85620, disclosed this week with a CVSS v4.0 score of 9.2, bypasses that entire control with a single syntactic trick. The […]

First report: Postgres MCP Pro Restricted-Mode Bypass Exposes the Gap in AI Database Security forkast.news, 10d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.