Postgres MCP Pro 0.3.0 restricted-mode bypass via RangeFunction
Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses, allowing attackers to execute file-reading functions and read arbitrary files.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to bypass restricted-mode protections and read arbitrary files.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-cm87-gp55-7cgj
