MEDIUM
TabularisDB
CVE published 2026-10-10
CVE-2026-108604
CVE-2026-108604 is a medium-severity vulnerability in Tabularis through version 0.27.0, which allows unauthorized modification of data by bypassing the read-only mode through the MCP run_query safety gate. This issue arises from an incorrect authorization vulnerability that enables prompt-injected agents or untrusted MCP clients to submit side-effecting SELECT statements, potentially leading to data modif [truncated]