Argument Injection Vulnerability in AWS Security Agent MCP Server
CVE-2026-97662
6.9MEDIUM
What is CVE-2026-97662?
An argument injection flaw in the diff scan operation of AWS security-agent-mcp-server before version 0.2.0 may allow threat actors to manipulate files on the host system by supplying specially crafted reference values. This manipulation can result in the creation, overwriting, or truncation of arbitrary files beyond the designated workspace directory, potentially compromising system integrity and security. Users are advised to upgrade to version 0.2.0 or later to mitigate this vulnerability.
Affected Version(s)
security-agent-mcp-server 0.1.1 < 0.2.0
