Junglewise Threat Intelligence

CVE-2026-97662: AWS security-agent-mcp-server argument injection in diff scan

CVE-2026-97662 · Severity: high · Published 2026-10-01

Technologies: Amazon AWS. Vendors: AWS, Amazon.

Executive brief

security-agent-mcp-server is an open-source tool that allows AI assistants to perform automated security scans on source code. An argument injection flaw in the diff scan feature allows an attacker to craft malicious input that bypasses file access restrictions and create, overwrite, or delete arbitrary files on the host system. This could enable an attacker to compromise the host system or corrupt critical data outside the intended workspace.

Technical details

An argument injection vulnerability exists in the diff scan operation where a crafted reference value is misinterpreted as a command-line option rather than a revision identifier. A context-dependent actor can supply malicious input to bypass the server's workspace-confinement control and perform file operations outside the intended directory. The vulnerability affects versions 0.1.1 through 0.1.x and is fixed in version 0.2.0.

Affected products

  • AWS security-agent-mcp-server >= 0.1.1, < 0.2.0

Timeline

  • 2026-10-01: disclosed: CVE-2026-97662 published by AWS

References

Related threats