CVE-2026-4270Disclosure(amazon / aws_api_mcp_server)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch amazon aws_api_mcp_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-424

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aws_api_mcp_server

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-16); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
aws_api_mcp_server

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-16: 1Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-05-15: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 1Technical Details · 2026-05-15: 103-1603-2103-2205-15
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-03-211
Disclosure1
2026-03-221
General1
2026-05-151
Patch1
Full discourse4 posts
  • AWS Security Digest@AwsSecDigest
    Patch

    Local File Inclusion in AWS Remote MCP Server via CLI Shorthand Syntax Coby Abrams Coby discovered an LFI (CVE-2026-4270) in the official AWS Remote MCP Server that completely bypasses FileAccessMode=NO_ACCESS. The AWS CLI’s shorthand for loading local file contents into command parameters was passed through unsanitized by the MCP server — point it at a sensitive file, trigger an error, and the error response leaks the file contents. Reproducible against http://aws-mcp.us-east-1.api.aws; patched in v1.3.9. 🔍 What matters: the vulnerability abuses CLI file-loading shorthand and server-side lack of input sanitization, not a client bug. ⚠️ Impact: secrets or config files can be exfiltrated via error messages even when NO_ACCESS is set. ✅ Fix: update AWS Remote MCP Server (and any forks) to v1.3.9 or later now. This was first mentioned in AWS Security Digest Issue #254: https://awssecuritydigest.com/past-issues/aws-security-digest-254 Read here: https://www.varonis.com/blog/local-file-inclusion-in-aws-remote-mcp-server

    Post summary

    CVE-2026‑4270 is a local file inclusion flaw in AWS Remote MCP Server exploited through CLI shorthand; the vulnerability is documented, patches to version 1.3.9 are available, and no active exploitation is reported.

    12054731
    1.7K followersView on X
  • Dar Fazulyanov@DarFazulyanov
    Disclosure

    MCP is becoming the #1 attack surface for AI agents, and most teams don't even know it exists. AWS just patched CVE-2026-4270 in their own MCP server. File access restrictions could be completely bypassed, exposing arbitrary local files to any connected AI agent.

    Post summary

    The note reports that AWS has patched CVE‑2026‑4270 on its MCP server, highlighting that the flaw allowed bypassing file‑access controls to read arbitrary local files for connected AI agents.

    2003055
    293 followersView on X
  • ナタリー 🌙@natalie_avfieb
    General

    AWSのMCPサーバで任意ファイルアクセスが可能になる脆弱性(CVE-2026-4270)、AIエージェントの攻撃面が具体化してきた。 「推論の裏側にある基盤」の信頼性が試されてる。自律させるなら、基盤の堅牢化はMCP Guard的な発想で一段深める必要がありそう。 #CyberSecurity #MCPGuard

    Post summary

    The post references CVE-2026-4270 as a vulnerability that permits arbitrary file access on AWS MCP servers, highlighting concerns about AI agent security but offering no specific exploitation, patch, or PoC details.

    0001095
    86 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4270 Path Traversal Vulnerability in AWS API MCP Server Versions 0.2.14 to 1.3.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4270

    Post summary

    This post announces a path traversal vulnerability (CVE-2026-4270) in AWS API MCP Server versions 0.2.14 to 1.3.8, with no information on PoC, exploit, or patch.

    0001069
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonaws_api_mcp_server-python-

Explore more