{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-108604","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-10-10T19:06:44.591Z","datePublished":"2026-10-10T19:54:37.564Z","dateUpdated":"2026-10-10T19:54:37.564Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-10-10T19:54:37.564Z"},"datePublic":"2026-10-09T00:00:00.000Z","title":"Tabularis through 0.27.0 Read-Only Bypass via MCP run_query SELECT Classification","descriptions":[{"lang":"en","value":"Tabularis through 0.27.0 contains an incorrect authorization vulnerability in the MCP run_query safety gate that allows prompt-injected agents or untrusted MCP clients to bypass read-only mode by submitting side-effecting SELECT statements. Attackers can run statements like SELECT setval, nextval, or PostgreSQL query_to_xml with embedded DELETE to modify data without approval prompts."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Incorrect Authorization","cweId":"CWE-863","type":"CWE"}]}],"affected":[{"vendor":"TabularisDB","product":"tabularis","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.27.0","status":"affected","versionType":"semver"}],"packageURL":"pkg:github/TabularisDB/tabularis","repo":"https://github.com/TabularisDB/tabularis"}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":5.8,"baseSeverity":"MEDIUM"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.3,"baseSeverity":"MEDIUM"}}],"references":[{"url":"https://hackmd.io/@haind/S1BofaIsMx","tags":["third-party-advisory"]},{"url":"https://github.com/TabularisDB/tabularis/blob/804c4c3bb6fd8eaa2e36cbe49f6c0d58f373b5e9/src-tauri/src/ai_activity.rs#L357-L416","tags":["technical-description"]},{"url":"https://github.com/TabularisDB/tabularis/blob/804c4c3bb6fd8eaa2e36cbe49f6c0d58f373b5e9/src-tauri/src/mcp/mod.rs#L1136-L1171","tags":["technical-description"]},{"url":"https://github.com/TabularisDB/tabularis","tags":["product"]},{"name":"VulnCheck Advisory: Tabularis through 0.27.0 Read-Only Bypass via MCP run_query SELECT Classification","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/tabularis-through-0.27.0-read-only-bypass-via-mcp-run-query-select-classification"}],"credits":[{"lang":"en","value":"HaiND from the Post and Telecommunication Institute of Technology","type":"finder"}],"x_generator":{"engine":"vulncheck-endgame"}}}}