bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: aws-healthomics-mcp-server

show all
Friday, July 17, 2026

AWS HealthOmics MCP Server Path Traversal Vulnerability – Update Required

AWS HealthOmics MCP Server versions 0.0.35 and earlier have a path traversal flaw (CVE-2026-15415) in workflow linters that could let attackers write files outside intended directories. If you're running aws-healthomics-mcp-server, upgrade to version 0.0.36 or later immediately. This affects the workflow_files input processing, so action is required if you use this service.

> source: aws.amazon.com