Skip to main content

CVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan

Bulletin ID: 2026-121-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/01/2026 10:30 AM PDT

Description:

security-agent-mcp-server is an open-source Model Context Protocol (MCP) server, published by AWS in the awslabs/mcp repository, that AI assistants use to run local security scans (including differential "diff" scans) over source code. We identified CVE-2026-97662, an argument injection issue in the diff scan operation: a crafted reference value supplied to the scan is interpreted as a command-line option rather than a revision, which lets a context-dependent actor create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory, bypassing the server's workspace-confinement control.

Impacted versions: >= 0.1.1 AND < 0.2.0

Resolution:

This issue has been addressed in security-agent-mcp-server version 0.2.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

There is no workaround other than upgrading. Until you upgrade, run diff scans only against trusted repositories, and run the server as a least-privileged user in an isolated environment so a stray write cannot reach sensitive host files.

References:

Acknowledgement:

We would like to thank Mario Guzmán (yud4s), independent researcher for collaborating on this issue through the coordinated vulnerability disclosure process.


Please email aws-security@amazon.com with any security questions or concerns..