CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
Bulletin ID: 2026-075-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/05/2026 12:30 PM PDT
Description:
The AWS Transform MCP Server (awslabs.aws-transform-mcp-server) is an open-source Model Context Protocol (MCP) server that runs locally on a developer's machine and lets AI-powered assistants interact with AWS Transform to run code-transformation jobs and retrieve their artifacts. We identified CVE-2026-18953. Improper limitation of a pathname to a restricted directory in the get_resource tool in awslabs.aws-transform-mcp-server before 0.1.5 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter, which could lead to local code execution.
Impacted versions: >=0.1.0 AND <=0.1.4
Resolution:
This issue has been addressed in awslabs.aws-transform-mcp-server version 0.1.5. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
There is no server-side or configuration-only workaround; the affected code path is present in the default configuration. Customers must upgrade to version 0.1.5 or later.
References:
Acknowledgement:
We would like to thank Drew Raines for collaborating on this issue through the coordinated issue disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.