Improper Endpoint Restriction in Amazon MQ MCP Server by AWS Labs
CVE-2026-18655
7.1HIGH
What is CVE-2026-18655?
An improper restriction of intended endpoints in the Amazon MQ MCP Server prior to version 2.0.24 may expose sensitive information such as broker credentials or OAuth access tokens. This occurs when a remote unauthenticated actor exploits a prompt injection vulnerability, allowing access to crafted endpoints controlled via broker hostnames in the MCP client context. Users are urged to upgrade to version 2.0.24 to mitigate this risk.
Affected Version(s)
amazon-mq-mcp-server 0 <= 2.0.23
