PT-2026-68306 · Amazon · Aws-Transform-Mcp-Server
CVE-2026-18953
·
Published
2026-08-05
·
Updated
2026-08-06
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Amazon awslabs.aws-transform-mcp-server versions 0.1.0 through 0.1.4
Description
Improper limitation of a pathname to a restricted directory in the
get resource() tool allows a context-dependent actor to write arbitrary files outside the intended working directory by manipulating the savePath parameter.Recommendations
Upgrade to version 0.1.5 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws-Transform-Mcp-Server