Vendor
Postgres MCP Pro version 0.3.0 is vulnerable to a restricted-mode bypass due to improper function-name validation within RangeFunction nodes in FROM clauses, enabling arbitrary file read.