MEDIUM🇵🇱 Wersja polska

CVE-2026-4270

CVSS 6.8v4.0pub. 2026-03-16upd. 2026-05-21

Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.

CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Amazon Aws Api Mcp Server

    APP
    Amazon
    0.2.14 – 1.3.9 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-77234CRITICAL9.3same vendor

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled por...

CVE-2026-35560CRITICAL9.1PL ✓same vendor

Nieprawidłowa walidacja certyfikatów w Amazon Athena ODBC Driver — atak MITM

CVE-2026-35561CRITICAL9.1PL ✓same vendor

Niewystarczające zabezpieczenia uwierzytelniania w Amazon Athena ODBC Driver

CVE-2025-20286CRITICAL9.9PL ✓same vendor

Cisco ISE w chmurze: współdzielone statyczne poświadczenia umożliwiają nieautoryzowany dostęp

CVE-2024-38373CRITICAL9.6PL ✓same vendor

Buffer over-read w parserze DNS biblioteki FreeRTOS-Plus-TCP