CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
Bulletin ID: 2026-097-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/04/2026 10:00 AM PDT
Description:
Amazon awslabs.dynamodb-mcp-server is an open-source Model Context Protocol (MCP) server that enables AI coding assistants to interact with Amazon DynamoDB, including table design, data modeling, and CDK infrastructure generation. We identified CVE-2026-85654, an improper neutralization of special elements used in a template engine in the CDK generator component. Under certain circumstances, a context-dependent actor could execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.
Impacted versions: >= 2.0.10 AND <= 2.1.5
Resolution:
This issue has been addressed in awslabs.dynamodb-mcp-server version 2.1.6. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
Users who cannot immediately upgrade should manually review the contents of dynamodb_data_model.json for unexpected or unintended table, index, or attribute names before running the CDK generator. Avoid using data model files from untrusted or unverified sources.
References:
Acknowledgement:
We would like to thank Jaimen Bell for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.