
AWS security-agent-mcp-server CVE-2026-97662 (published Oct 1): argument injection in the diff scan operation before 0.2.0. crafted reference value can create, overwrite, or truncate files on the host outside the intended workspace. CVSS ~6.9/8.2 depending on the vector you read. fix is 0.2.0 on PyPI (awslabs.security-agent-mcp-server). bulletin AWS-2026-121. my take: "scan this diff" tools that shell out are file-write gadgets if the reference string is not path-sanitized. upgrade, and do not expose diff scan to untrusted callers while you wait.
