{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/postgres/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:postgres:mcp_pro:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-85620"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Postgres MCP Pro (0.3.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Postgres"],"content_html":"\u003cp\u003ePostgres MCP Pro version 0.3.0 contains a vulnerability (CVE-2026-85620) that allows for a restricted-mode bypass. The flaw resides in the handling of RangeFunction nodes within SQL FROM clauses. Specifically, the application fails to apply necessary function-name validation logic to these nodes, allowing an attacker to invoke sensitive functions that are intended to be restricted. By crafting specific SQL queries that utilize these functions within a FROM clause, an attacker can bypass defined security constraints to execute functions such as pg_read_file. This results in unauthorized access to arbitrary files residing on the host system. This vulnerability is significant for defenders as it allows for information disclosure, potentially leading to the extraction of sensitive credentials, configuration files, or system data, depending on the permissions of the Postgres service account.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-85620 grants an attacker the ability to read arbitrary files from the filesystem of the server hosting the Postgres MCP Pro service. This compromise can lead to the exfiltration of sensitive information, including configuration files, local keys, and system metadata, which may be leveraged for further privilege escalation or lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit database logs for SQL queries containing both 'FROM' and 'pg_read_file' or other file-access functions within the same statement.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for unauthorized attempts to access sensitive file paths (e.g., /etc/passwd, .ssh/id_rsa) via database-linked functions.\u003c/li\u003e\n\u003cli\u003eUpgrade Postgres MCP Pro to a version that addresses CVE-2026-85620 as soon as the vendor releases a patch.\u003c/li\u003e\n\u003cli\u003eRestrict the permissions of the database service account to the absolute minimum necessary for business operations to limit the impact of potential file-read exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:28:04Z","date_published":"2026-09-04T15:28:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-postgres-mcp-bypass/","summary":"Postgres MCP Pro version 0.3.0 is vulnerable to a restricted-mode bypass due to improper function-name validation within RangeFunction nodes in FROM clauses, enabling arbitrary file read.","title":"Postgres MCP Pro Restricted Mode Bypass (CVE-2026-85620)","url":"https://feed.craftedsignal.io/briefs/2026-09-postgres-mcp-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Postgres","version":"https://jsonfeed.org/version/1.1"}