AWS Amazon MQ MCP Server: Critical Credential Leak via Prompt Injection
AWS Amazon MQ MCP Server versions up to 2.0.23 have a nasty vulnerability (CVE-2026-18655) that lets attackers snag your broker credentials and OAuth tokens through prompt injection. The flaw affects RabbitMQ connection tools—basically, a crafted endpoint can trick the system into leaking sensitive auth data. You need to upgrade to version 2.0.24 or later immediately. This one's serious and requires immediate action.