CVE-2026-97662

Summary

An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation.

To remediate this issue, users should upgrade to version 0.2.0.

Affected Software

VendorProductVersion RangeStatus
AWSsecurity-agent-mcp-server0.1.1 < 0.2.0affected

Weaknesses

  • CWE-88: CWE-88 Improper neutralization of argument delimiters in a command ('argument injection')
  • CWE-73: CWE-73 External control of file name or path

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References