AWS read-only Postgres MCP server hit by COPY command injection
AWS disclosed CVE-2026-87911 (CVSS 9.6): a command injection in the read-only enforcement of postgres-mcp-server lets a crafted COPY ... TO PROGRAM statement run OS commands on the database host. The fix shipped in version 1.1.7 back in June, but the issue only surfaced with the September 9 advisory.
- CVE-2026-87911: command injection in read-only postgres-mcp-server, CVSS 9.6
- A single COPY (SELECT 1) TO PROGRAM line runs commands on the DB host
- BEGIN READ ONLY does not block COPY TO PROGRAM — effects fall outside table data
- Self-managed Postgres with superuser or pg_execute_server_program roles is affected
Read next
Software