Critical Vulnerability (CVE-2026-85620) in Postgres MCP Pro Bypasses AI Database Security Controls

AI-generated NewsSnap summary based on source reporting.
Published: 2026-09-05
Category: technology
Source: Cybersecurity News

A critical vulnerability, CVE-2026-85620 (CVSS v4.0 score of 9.2), has been disclosed in Postgres MCP Pro, a popular Model Context Protocol server. This flaw allows attackers to bypass application-layer safety controls, including read-only transactions and SQL allowlists, by exploiting an incomplete validation in the SQL safety layer. This can lead to arbitrary file reads and potential escalation from database queries to host filesystem access, highlighting a significant security gap in AI database interactions.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai