
Local File Inclusion in AWS Remote MCP Server via CLI Shorthand Syntax Coby Abrams Coby discovered an LFI (CVE-2026-4270) in the official AWS Remote MCP Server that completely bypasses FileAccessMode=NO_ACCESS. The AWS CLI’s shorthand for loading local file contents into command parameters was passed through unsanitized by the MCP server — point it at a sensitive file, trigger an error, and the error response leaks the file contents. Reproducible against http://aws-mcp.us-east-1.api.aws; patched in v1.3.9. 🔍 What matters: the vulnerability abuses CLI file-loading shorthand and server-side lack of input sanitization, not a client bug. ⚠️ Impact: secrets or config files can be exfiltrated via error messages even when NO_ACCESS is set. ✅ Fix: update AWS Remote MCP Server (and any forks) to v1.3.9 or later now. This was first mentioned in AWS Security Digest Issue #254: https://awssecuritydigest.com/past-issues/aws-security-digest-254 Read here: https://www.varonis.com/blog/local-file-inclusion-in-aws-remote-mcp-server
Post summary
CVE-2026‑4270 is a local file inclusion flaw in AWS Remote MCP Server exploited through CLI shorthand; the vulnerability is documented, patches to version 1.3.9 are available, and no active exploitation is reported.



