PT-2026-109749 · Tabularisdb · Tabularis
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H |
Tabularis through 0.27.0 contains an incorrect authorization vulnerability in the MCP run query safety gate that allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements. Attackers can run statements like SELECT setval, nextval, or PostgreSQL query to xml with embedded DELETE to modify data without approval prompts.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tabularis