Home

Description

aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system.

PUBLISHED Reserved 2025-05-27 | Published 2025-05-28 | Updated 2025-05-28 | Assigner snyk




CRITICAL: 9.4CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CRITICAL: 9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Problem types

OS Command Injection

Product status

Any version before 1.3.0
affected

Credits

Raul Onitza-Klugman (Snyk Security Research)

References

github.com/...ommit/94d20ae1798a43ac7e3a28e71900d774e5159c8a

github.com/...774e5159c8a/src/aws_mcp_server/cli_executor.py

cve.org (CVE-2025-5277)

nvd.nist.gov (CVE-2025-5277)

Download JSON