Improper Directory Limitation in Amazon awslabs.aws-transform-mcp-server Tool
CVE-2026-18953
6.3MEDIUM
What is CVE-2026-18953?
The awslabs.aws-transform-mcp-server tool from Amazon contains a vulnerability due to improper validation of the savePath parameter, which could allow an attacker to write files outside the designated working directory. This issue affects versions 0.1.0 through 0.1.4. Users are encouraged to upgrade to version 0.1.5 or later to address this security risk effectively.
Affected Version(s)
aws-transform-mcp-server 0.1.0 <= 0.1.4
