Skip to main content

CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server

Bulletin ID: 2026-075-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/05/2026 12:30 PM PDT

Description:

The AWS Transform MCP Server (awslabs.aws-transform-mcp-server) is an open-source Model Context Protocol (MCP) server that runs locally on a developer's machine and lets AI-powered assistants interact with AWS Transform to run code-transformation jobs and retrieve their artifacts. We identified CVE-2026-18953. Improper limitation of a pathname to a restricted directory in the get_resource tool in awslabs.aws-transform-mcp-server before 0.1.5 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter, which could lead to local code execution.

Impacted versions: >=0.1.0 AND <=0.1.4

Resolution:

This issue has been addressed in awslabs.aws-transform-mcp-server version 0.1.5. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

There is no server-side or configuration-only workaround; the affected code path is present in the default configuration. Customers must upgrade to version 0.1.5 or later.

References:

Acknowledgement:

We would like to thank Drew Raines for collaborating on this issue through the coordinated issue disclosure process.


Please email aws-security@amazon.com with any security questions or concerns.