Home
CRITICAL: 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HCRITICAL: 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Any version before 1.3.0
affected
Description
aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system.
Problem types
Product status
Credits
Raul Onitza-Klugman (Snyk Security Research)
References
github.com/...ommit/94d20ae1798a43ac7e3a28e71900d774e5159c8a
github.com/...774e5159c8a/src/aws_mcp_server/cli_executor.py