CVE-2026-97662

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation. To remediate this issue, users should upgrade to version 0.2.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-03: 110-03
Full discourse1 post
  • Sagar Tanur 🇮🇳@Sagarvd01

    AWS security-agent-mcp-server CVE-2026-97662 (published Oct 1): argument injection in the diff scan operation before 0.2.0. crafted reference value can create, overwrite, or truncate files on the host outside the intended workspace. CVSS ~6.9/8.2 depending on the vector you read. fix is 0.2.0 on PyPI (awslabs.security-agent-mcp-server). bulletin AWS-2026-121. my take: "scan this diff" tools that shell out are file-write gadgets if the reference string is not path-sanitized. upgrade, and do not expose diff scan to untrusted callers while you wait.

    1001044
    178 followersView on X

Explore more