From tramlines.io here - We found a similar exploit in the official Neon DB MCP -
https://www.tramlines.io/blog/neon-official-remote-mcp-explo...Hah, yeah that's the exact same vulnerability - looks like Neon's MCP can be setup for read-write access to the database, which is all you need to get all three legs of the lethal trifecta (access to private data, exposure to malicious instructions and the ability to exfiltrate).