Improper Neutralization Vulnerability in Amazon Awslabs DynamoDB MCP Server
CVE-2026-85654

7.1HIGH

Key Information:

Vendor

Amazon

Vendor
CVE Published:
4 September 2026

What is CVE-2026-85654?

The Amazon Awslabs DynamoDB MCP Server is affected by a vulnerability where improper neutralization of special elements utilized in its template engine can lead to potential arbitrary code execution. This occurs when context-dependent actors exploit crafted table, index, or attribute names within a data model file, facilitating the execution of malicious code on the hosting environment. Users of versions prior to 2.1.6 are particularly at risk and should update to mitigate this issue.

Affected Version(s)

awslabs.dynamodb-mcp-server 2.0.10 <= 2.1.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.