logo

MCP vulnerability case study: SQL injection in the Postgres MCP server

ID: 223acba8-3ec3-5a67-ba72-401d2a7973c9

STIX ID: report--223acba8-3ec3-5a67-ba72-401d2a7973c9

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2025-08-21

Date Updated: 2026-04-27

...
...

**Executive summary:** Datadog security research identified a SQL injection flaw in the archived Anthropic Postgres MCP server (v0.6.2 on NPM) that permits stacked SQL statements to break out of enforced read-only transactions (for example by issuing COMMIT;) and perform arbitrary write operations or change session variables; a working proof-of-concept and exploitation scenarios (including DROP SCHEMA) are provided, and fixes are available in a Zed Industries fork and an upstream pull request—users are advised to avoid the deprecated server in production or migrate to patched builds and follow least-privilege practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.