AWS security-agent-mcp-server Vulnerable to Argument Injection Attack
AWS security-agent-mcp-server (versions 0.1.1–0.2.0) has a critical argument injection flaw in its diff scan feature. An attacker can craft malicious reference values to execute arbitrary file operations outside the workspace, bypassing security controls. If you're using affected versions, update immediately to patch this vulnerability.
source: [aws/security-bulletin]