Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Postgres MCP Pro 0.3.0 restricted-mode bypass via RangeFunction

Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses, allowing attackers to execute file-reading functions and read arbitrary files.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to bypass restricted-mode protections and read arbitrary files.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-cm87-gp55-7cgj