CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108604

MEDIUMCVSS 6.3NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

Tabularis through 0.27.0 contains an incorrect authorization vulnerability in the MCP run_query safety gate that allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements. Attackers can run statements like SELECT setval, nextval, o

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-108604 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108604

MEDIUMCVSS 6.3NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

Tabularis through 0.27.0 contains an incorrect authorization vulnerability in the MCP run_query safety gate that allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements. Attackers can run statements like SELECT setval, nextval, o

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]