Argument injection in AWS security-agent-mcp-server diff scan
High8.2CVE-2026-97662 · Published Oct 1, 2026
Bulletin ID: 2026-121-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 10:30 AM PDT Description: security-agent-mcp-server is an open-source Model Context Protocol (MCP) server, published by AWS in the awslabs/mcp repository, that AI assistants use to run local security scans (including differential "diff" scans) over source code. We identified CVE-2026-97662, an argument injection issue in the diff scan operation: a crafted reference value supplied to the scan is interpreted as a command-line option rather than a revision, which lets a context-dependent actor create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory, bypassing the server's workspace-confinement control. Impacted versions: >= 0.1.1 AND < 0.2.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Oct 2 | Severity: Unrated to High |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
- Severity from
- NVD
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python) | Medium5.3 | No fix yet |
| Oct 1 | Uncontrolled recursion in the Ion reader in Amazon Ion Python | High7.5 | No fix yet |
| Oct 1 | Mount Option Injection in Amazon EFS CSI Driver | Medium6.5 | No fix yet |
| Sep 29 | GluonTS arbitrary command execution during model deserialization | High7.8 | No fix yet |
| Sep 25 | REMOVE_BASE_PATH strips every leading repetition of the base path, not just one | Low | 1.1.0 |
| Sep 24 | Type confusion in AWS pgcollection allows remote code execution | High8.8 | No fix yet |