bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: AWS Transform MCP Server

show all
Wednesday, August 5, 2026

AWS Transform MCP Server Path Traversal Vulnerability – Update Required

AWS Transform MCP Server versions 0.1.0 through 0.1.4 have a path traversal flaw (CVE-2026-18953) that lets attackers write files outside the intended directory via the savePath parameter, potentially enabling local code execution. If you're running this open-source MCP server locally, you need to upgrade to version 0.1.5 or later immediately. This is a context-dependent attack, but the risk is real for developers using AI assistants with AWS Transform integration.

> source: aws.amazon.com