bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: security policy

show all
Thursday, July 23, 2026

AWS API MCP Server Security Policy Bypass – Update Required

AWS API MCP Server (awslabs.aws-api-mcp-server) versions 0.2.13 through 1.3.46 have a critical flaw: if the security policy fails to load on startup, the server keeps running without enforcing access controls. This means configured policy denials get bypassed for the entire process lifetime. If you're using this tool with a security policy, update to version 1.3.47 or later immediately—especially if fail-closed modes aren't enabled.

> source: aws.amazon.com