Skip to main content

CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection

Bulletin ID: 2026-070-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/03/2026 12:00 PM PDT

Description:

AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers.

We identified CVE-2026-18655, an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may allow a remote unauthenticated actor to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.

Impacted versions: <= 2.0.23

Resolution:

This issue has been addressed in awslabs.amazon-mq-mcp-server version 2.0.24. We recommend upgrading to the latest version and ensuring any forked or derivative code is also patched followed by rotating broker credentials.

Workarounds:

In the interim, do not use auto-approve for the rabbimq_broker_initialize_connection or rabbimq_broker_initialize_connection_with_oauth tools. This ensures a user must visually inspect the broker_hostname argument before it executes, and can reject calls with hostnames that do not match the expected Amazon MQ endpoint pattern (e.g., <broker_id>.mq.<region>.on.aws).

References:

Acknowledgement:

We would like to thank Marios Gyftos for collaborating on this issue through the coordinated vulnerability disclosure process.


Please email aws-security@amazon.com with any security questions or concerns.