Impact
The vulnerability arises because function‑name validation is omitted for RangeFunction nodes found in FROM clauses. This omission allows an attacker to invoke file‑reading functions such as pg_read_file by crafting a query that uses a function in the FROM clause. The attacker can thereby read any file the database process can access, leading to potential disclosure of sensitive configuration or data files and broader system compromise.
Affected Systems
The affected vendor is crystaldba, and the product is Postgres MCP Pro version 0.3.0. No additional versions or products are listed as impacted.
Risk and Exploitability
The vulnerability scores a CVSS of 9.2 and is not listed in the CISA KEV catalog, suggesting no known widespread exploitation so far. Because EPSS data is unavailable the precise exploitation probability is unclear, but the straightforward nature of the flaw means that, given DB access and the ability to run a query, an attacker can retrieve arbitrary files. The impact is high confidentiality impact and the potential to open further privilege escalation vector.
OpenCVE Enrichment