PT-2026-109749 · Tabularisdb · Tabularis

·

CVE-2026-108604

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Tabularis through 0.27.0 contains an incorrect authorization vulnerability in the MCP run query safety gate that allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements. Attackers can run statements like SELECT setval, nextval, or PostgreSQL query to xml with embedded DELETE to modify data without approval prompts.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-108604

Affected Products

Tabularis