chiprook
← Security
SecurityOctober 4, 2026, 07:18

AWS read-only Postgres MCP server hit by COPY command injection

AWS disclosed CVE-2026-87911 (CVSS 9.6): a command injection in the read-only enforcement of postgres-mcp-server lets a crafted COPY ... TO PROGRAM statement run OS commands on the database host. The fix shipped in version 1.1.7 back in June, but the issue only surfaced with the September 9 advisory.

AWS read-only Postgres MCP server hit by COPY command injection
#AWS#Postgres#MCP
Read next
Software

AWS ships official agent toolkit with MCP servers and plugins

Software

Stateless MCP Removes Session Affinity for AWS Server Deployments

Security

Semicolon in a Codex branch name leaked GitHub token via command injection

Security

Deno CVE-2026-103473: CVSS 8.1 command injection in node:child_process on Windows