Server-Side Request Forgery in AWS HealthLake MCP Server by AWS
CVE-2026-15643
9.2CRITICAL
What is CVE-2026-15643?
The AWS HealthLake MCP Server, used for enabling AI assistants to interact with AWS HealthLake FHIR datastores, is vulnerable to a server-side request forgery due to improper validation in its pagination handling. Specifically, an attacker can exploit this vulnerability by crafting a malicious next_token parameter, which can result in the exfiltration of AWS temporary security credentials. The vulnerability exists in versions prior to 0.0.14 and allows authenticated users to redirect requests to malicious endpoints, posing serious security risks. To mitigate this vulnerability, it is crucial to upgrade to version 0.0.14 or later.
Affected Version(s)
awslabs.healthlake-mcp-server 0 < 0.0.14
