PROBLEM
MCP - User discovered excessive permissions exposed by MCP inte...
User discovered excessive permissions exposed by MCP integrations, including ability to execute arbitrary SQL and delete repositories.
Updated: 4/15/2026
I tried something simple last month.
Connected a Postgres MCP to one of our bots. Wanted read access.
The server also exposed DELETE, execute arbitrary SQL, and DROP TABLE.
GitHub MCP — added for code reading. Also had delete_repository.
Slack MCP — wanted search. Got https://t.co/1gDzJiJD2C
Source: https://x.com/navinsharmacse/status/2037162035084202060
Did this solve your problem?
0 developers found this helpful