Vulnerability  ·  2026-10-02

AWS security-agent-mcp-server diff-scan argument injection escapes workspace confinement to write arbitrary host files

VulnerabilityHigh impactGlobalCVE-2026-97662
AWS disclosed via coordinated disclosure (credited yud4s) an argument-injection flaw in the diff-scan operation of its official security-agent MCP server: an attacker-controlled 'reference' value flows into a CLI invocation as an option rather than a revision, defeating the intended workspace-confinement and enabling file write/truncate outside the sandbox.
This is an official AWS MCP server whose entire purpose is to let LLM agents run code-scanning commands on the host. Because agent tool output is semi-trusted by design, an argument-injection escape from workspace confinement converts agent instructions into host file tampering — a textbook agentic tooling risk on an AWS-blessed component.
A crafted reference value supplied to the diff-scan operation is interpreted as a command-line option rather than a revision (argument injection), letting a context-dependent actor create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory — bypassing the server's workspace-confinement control (CVSS 8.2).
AWS security-agent-mcp-server (awslabs/mcp) >= 0.1.1 and < 0.2.0
Upgrade to security-agent-mcp-server 0.2.0 (AWS Security Bulletin 2026-121-AWS); no workaround — until patched, only run diff scans against trusted repos and run the server least-privileged in an isolated environment
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →