Impact
The vulnerability is an incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server. The weakness can allow an unauthenticated actor to craft SQL that bypasses read‑only restrictions and modify data in the database. The primary impact is unauthorized data modification and potential escalation of privilege, as the flaw is classified under CWE‑184, which denotes unsafe string evaluation that can lead to injection attacks.
Affected Systems
The affected product is Amazon's postgres-mcp-server. Versions prior to 1.1.7 are impacted; version 1.1.7 and later contain the fix. No additional versions are enumerated in the CNA data.
Risk and Exploitability
The CVSS score is 7.1, indicating a moderate‑to‑high risk. The EPSS score is not available, so the exploitation probability is unknown. The flaw is not listed in CISA's KEV catalog. The likely attack vector involves an unauthenticated actor supplying crafted content that is later submitted by an authenticated user to the MCP server, enabling the execution of unintended SQL statements.
OpenCVE Enrichment