Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Crystaldba
Crystaldba postgres-mcp |
|
| Vendors & Products |
Crystaldba
Crystaldba postgres-mcp |
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections. | |
| Title | Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:32:11.907Z
Reserved: 2026-09-04T11:03:33.315Z
Link: CVE-2026-85620
No data.
Status : Received
Published: 2026-09-04T15:17:42.150
Modified: 2026-09-04T15:17:42.150
Link: CVE-2026-85620
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:30:07Z
