Reported issues for PostgreSQL MCP Server by YawLabs
Pod holds 5 of 5 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to PostgreSQL MCP Server by YawLabs.
Most discussed
pg_kill's raw pool checkout has no error listener: a connection that drops mid-call takes the whole server down
Context
0.13.2 fixed "the server exits when a connection it has checked out dies" by routing checkouts through acquireClient() (src/api.ts:652), which keeps an error listener on the client for as long as it is out. The changelog says "Every checkout now carries a listener for as long as it is out" (CHANGELOG.md:22).
One checkout was missed. pg_kill calls getPool().connect() itself (src/tools/admin.ts:505) and attaches only a notice listener (:510). It is the only checkout…
Read the thread · 2026-09-18 · closed · 0 comments
pg_kill documents a permission denial as signaled: false plus a NOTICE; postgres raises 42501 and the tool returns an error
Context
pg_kill's description, its output-schema comment and its handler comment all say a permission denial comes back as a successful response: signaled: false, with postgres's NOTICE in note. It does not. PostgreSQL raises (SQLSTATE 42501) when the role may not signal the target, so pg_kill returns an error and note is never built.
Where the wrong contract is stated (main at a94cf1f):
src/tools/admin.ts:453-456, the agent-facing tool description: "When…
Read the thread · 2026-09-18 · closed · 0 comments
POSTGRES_MCP_SANDBOX fails open: typo'd value, Node fallback, and host-less DATABASE_URL all run unsandboxed without a word
Context
POSTGRES_MCP_SANDBOX=1 asks the launcher to run the server under oam's --permission model. Filesystem and child processes are denied, and the network is pinned to the database's host:port (bin/postgres-mcp.mjs:36-43). Four measured paths leave the operator believing they are sandboxed when they are not. In none of them does anything on stderr mention the sandbox.
1. Any value other than exactly 1 is ignored
bin/postgres-mcp.mjs:166 - `if…
Read the thread · 2026-09-12 · closed · 0 comments
An empty POSTGRES_AUDIT_LOG or POSTGRES_AUDIT_REDACT silently reads as unset -- the failure strict parsing exists to prevent
Context
src/audit.ts:18-23 explains why audit config is parsed strictly. A typo'd value must not read as "off", because "a security control that quietly disables itself is worse than none". POSTGRES_AUDIT_REDACT=yes is singled out as dangerous, since it would silently write full SQL.
An empty value slips past that rule, for both flags:
src/audit.ts:81-82-const value = raw.trim().toLowerCase(); if (value === "") return null;src/audit.ts:96- `POSTGRES_AUDIT_REDACT ...…
Read the thread · 2026-09-12 · closed · 0 comments
pg_kill writes no audit line: the only tool that signals other backends is invisible to POSTGRES_AUDIT_LOG
Context
Every tool's SQL reaches the audit log through one of three helpers in src/api.ts: runUserQueryAudited (:476), runInternal (:699), or the withSharedClient runner (:771). pg_kill uses none of them. It takes a raw client and queries it directly:
src/tools/admin.ts:505-const client = await getPool().connect();src/tools/admin.ts:512-client.query(SELECT ${fn}($1) AS signaled, [pid])
So with auditing on, cancelling a query or terminating a backend…
Read the thread · 2026-09-12 · closed · 0 comments
Most recent
The remaining reports are on the project's issue tracker.