Vulnerability Description
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should upgrade to version 0.1.5 or later.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://aws.amazon.com/security/security-bulletins/2026-075-aws/
- https://github.com/awslabs/mcp/security/advisories/GHSA-66mr-jr63-2jgw
- https://pypi.org/project/awslabs.aws-transform-mcp-server/0.1.5/
FAQ
What is CVE-2026-18953?
CVE-2026-18953 is a vulnerability with a CVSS score of 8.6 (HIGH). Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbit...
How severe is CVE-2026-18953?
CVE-2026-18953 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18953?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.