70
/ 100
1 month ago
glama

PostgreSQL SSH MCP Server

A secure PostgreSQL MCP server with built-in SSH tunneling that enables AI assistants to connect to databases through bastion hosts automatically, supporting both STDIO and Streamable HTTP transports.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical, 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 3 credentials: DATABASE_PASSWORD, SSH_PASSWORD, SSH_STRICT_HOST_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 critical2 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@2.1.8GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

criticalvitest@2.1.8GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

high@modelcontextprotocol/sdk@1.25.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.25.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAUTH0_AUDIENCEYes Auth0 API identifier / audience
configAUTH0_DOMAINYes Auth0 tenant domain (e.g., tenant.us.auth0.com)
configDATABASE_HOSTYes — Database hostname
configDATABASE_NAMEYes — Database name
🔐 secretDATABASE_PASSWORDYes — Database password
configDATABASE_PORTNo 5432 Database port
configDATABASE_SSLAuto true or false. Auto-enabled for non-localhost.
configDATABASE_SSL_CAPath to CA certificate bundle
configDATABASE_SSL_REJECT_UNAUTHORIZEDtrue Set false to allow self-signed certificates
configDATABASE_URI"": "postgresql://user:password@localhost:5432/mydb"
configDATABASE_USERYes — Database username
configMAX_CONCURRENT_QUERIES10 Maximum concurrent queries
configMAX_ROWSexecute_query Execute SQL with parameterized queries. Results capped by .
configMCP_ALLOWED_HOSTSComma-separated allowed Host headers
configMCP_ALLOWED_ORIGINSComma-separated allowed CORS origins ( for any)
configMCP_AUTH_MODEnone Authentication mode: none or oauth
configMCP_HOST0.0.0.0 HTTP server bind address
configMCP_RESOURCE_DOCUMENTATIONNo URL to API documentation (RFC 9728)
configMCP_SERVER_POOL_SIZE4 Server instances for stateless mode
configMCP_SESSION_CLEANUP_INTERVAL_MS300000 Session cleanup interval
configMCP_SESSION_TTL_MINUTES30 Session TTL for stateful mode
configMCP_STATELESStrue Stateless mode (each request re-initializes)
configPOOL_DRAIN_TIMEOUT_MS5000 Timeout for draining pool during reconnect
configPORT3000 HTTP server port
configQUERY_TIMEOUT30000 Query timeout in milliseconds
configREAD_ONLYtrue Block data modifications. Set false to allow writes.
configSSH_ENABLEDNo false Set true to enable SSH tunneling
configSSH_HOSTYes — SSH server hostname
configSSH_KEEPALIVE_INTERVALNo 10000 Keepalive interval in milliseconds
configSSH_KNOWN_HOSTS_PATHNo ~/.ssh/known_hosts Custom known_hosts file
configSSH_MAX_RECONNECT_ATTEMPTSNo 5 Max reconnect attempts (-1 for unlimited)
🔐 secretSSH_PASSWORDYes — SSH password (alternative to key)
configSSH_PORTNo 22 SSH server port
configSSH_PRIVATE_KEY_PASSPHRASENo — Passphrase for encrypted keys
configSSH_PRIVATE_KEY_PATHYes — Path to private key file
🔐 secretSSH_STRICT_HOST_KEYNo true Verify host key against known_hosts
configSSH_TRUST_ON_FIRST_USENo true Auto-add unknown hosts (when strict is enabled)
configSSH_USERYes — SSH username
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/zlash65-postgresql-ssh-mcp-144p9r)](https://m8ven.ai/mcp/zlash65-postgresql-ssh-mcp-144p9r)
commit: 2a350d45d464820df349c9b21cb178dcb74cc230
code hash: 2fa630af4d97e1c98cdaaa1dc08f4db783624f9d73894d35720df8c7ee32aea8
verified: 6/13/2026, 10:19:34 AM
view raw JSON →