MEDIUM 6.9 NVD
CVE-2026-97662
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to crea
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation.
To remediate this issue, users should upgrade to version 0.2.0.
References
- https://aws.amazon.com/security/security-bulletins/2026-121-aws/
- https://pypi.org/project/awslabs.security-agent-mcp-server/0.2.0/
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-10-01 via NVD.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.