Skip to content
AWSAWS-2026-121

Argument injection in AWS security-agent-mcp-server diff scan

High8.2CVE-2026-97662 · Published Oct 1, 2026

Bulletin ID: 2026-121-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 10:30 AM PDT Description: security-agent-mcp-server is an open-source Model Context Protocol (MCP) server, published by AWS in the awslabs/mcp repository, that AI assistants use to run local security scans (including differential "diff" scans) over source code. We identified CVE-2026-97662, an argument injection issue in the diff scan operation: a crafted reference value supplied to the scan is interpreted as a command-line option rather than a revision, which lets a context-dependent actor create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory, bypassing the server's workspace-confinement control. Impacted versions: >= 0.1.1 AND < 0.2.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

DateChange
Oct 2Severity: Unrated to High
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
Severity from
NVD

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.