Improper limitation of a pathname in AWS Transform MCP Server
UnratedCVE-2026-18953 · Published Aug 5, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-075-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 12:30 PM PDT Description: The AWS Transform MCP Server (awslabs.aws-transform-mcp-server) is an open-source Model Context Protocol (MCP) server that runs locally on a developer's machine and lets AI-powered assistants interact with AWS Transform to run code-transformation jobs and retrieve their artifacts. We identified CVE-2026-18953 . Improper limitation of a pathname to a restricted directory in the get_resource tool in awslabs.aws-transform-mcp-server before 0.1.5 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter, which could lead to local code execution. Impacted versions: >=0.1.0 AND Resolution: This issue has been addressed in awslabs.aws-transform-mcp-server version 0.1.5 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There is no server-side or configuration-only workaround; the affected code path is present in the default configuration. Customers must upgrade to version 0.1.5 or later....
Affected versions
Details and references
Bulletin ID: 2026-075-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 12:30 PM PDT Description: The AWS Transform MCP Server (awslabs.aws-transform-mcp-server) is an open-source Model Context Protocol (MCP) server that runs locally on a developer's machine and lets AI-powered assistants interact with AWS Transform to run code-transformation jobs and retrieve their artifacts. We identified CVE-2026-18953 . Improper limitation of a pathname to a restricted directory in the get_resource tool in awslabs.aws-transform-mcp-server before 0.1.5 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter, which could lead to local code execution. Impacted versions: >=0.1.0 AND Resolution: This issue has been addressed in awslabs.aws-transform-mcp-server version 0.1.5 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There is no server-side or configuration-only workaround; the affected code path is present in the default configuration. Customers must upgrade to version 0.1.5 or later. References: CVE-2026-18953 GHSA-66mr-jr63-2jgw Acknowledgement: We would like to thank Drew Raines for collaborating on this issue through the coordinated issue disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-075-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server Bulletin ID: 2026-075-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/05/2026 12:30 PM PDT Description: The AWS Transform MCP Server (awslabs.aws-transform-mcp-server) is an open-source Model Context Protocol (MCP) server that runs locally on a developer's machine and lets AI-powered assistants interact with AWS Transform to run code-transformation jobs and retrieve their artifacts. We identified CVE-2026-18953 . Improper limitation of a pathname to a restricted directory in the get_resource tool in awslabs.aws-transform-mcp-server before 0.1.5 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter, which could lead to local code execution. Impacted versions: >=0.1.0 AND Resolution: This issue has been addressed in awslabs.aws-transform-mcp-server version 0.1.5 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: There is no server-side or configuration-only workaround; the affected code path is present in the default configuration. Customers must upgrade to version 0.1.5 or later. References: CVE-2026-18953 GHSA-66mr-jr63-2jgw Acknowledgement: We would like to thank Drew Raines for collaborating on this issue through the coordinated issue disclosure process. Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccount
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 6 | Insecure direct object reference in Strands Agents Tools memory tools | Unrated | No fix yet |
| Aug 5 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB... | Unrated | No fix yet |
| Aug 4 | AWS: code execution | Unrated | No fix yet |
| Aug 4 | Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation | Unrated | No fix yet |
| Aug 3 | Disabled SSH host key verification in AWS CLI EMR helper commands | Unrated | No fix yet |
| Aug 3 | Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt... | Unrated | No fix yet |