pgvector 0.8.7 fixes an IVFFlat index-build overflow that could run code
pgvector, the PostgreSQL extension that adds vector similarity search and sits under many retrieval-augmented AI applications, released version 0.8.7 on 1 October with a security fix. The PostgreSQL project's news page also carries the announcement.
The bug. According to the project's advisory, a database user with the ability to create an IVFFlat index could write data out of bounds during the index build, which can lead to arbitrary code execution. It is tracked as CVE-2026-103484 and affects 0.8.6 and every earlier version. The issue was reported by researchers at Compass Security. The maintainer's advice is that all users of an affected version should upgrade when possible.
Not the first one. The changelog shows that 0.8.6, released on 29 July, fixed a buffer overflow in the same place, IVFFlat index builds, but only on 32-bit systems. The new fix applies everywhere. 0.8.7 also fixes an error with the avg aggregate when no rows match.
Who is exposed. The precondition matters: the attacker needs to be a database user allowed to create an index on a table with a vector column. In a typical single-application database that is the application's own role, so the risk is mostly about what that role can be tricked into running. It is larger in shared or multi-tenant Postgres setups, and in tools that let users or AI agents run SQL with index-creation rights. Code execution inside the database server process means access beyond the attacker's own tables.
Upgrading. pgvector is a compiled extension, so the new binaries have to be installed on the server and the extension updated in each database with ALTER EXTENSION vector UPDATE. Managed Postgres providers ship pgvector themselves and decide when 0.8.7 becomes available, so users of hosted databases should check their provider's extension version rather than assume it.

What it means
Vector search moved from experiment to infrastructure quickly, and its extensions now carry the same class of memory-safety bugs as any C code inside a database. Treat pgvector like any other server component: track its releases, and limit which roles can create indexes where untrusted SQL can run.