Security flaw found in Postgres AI agent tool using read-only transactions

A reference Postgres MCP server published by the Model Context Protocol project contained a security vulnerability where AI agents could bypass read-only transaction guards. The server ran agent queries inside BEGIN TRANSACTION READ ONLY blocks, but agents could send multiple statements in one query string, including COMMIT commands. This allowed malicious commands like DROP TABLE to execute after the read-only transaction ended. Security researchers at Datadog documented this SQL injection vulnerability in August 2025. The repository was archived in May 2025 with a warning that no security updates would be provided.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in