Amazon aws-cli是美国Amazon公司的一个与云服务交互的命令行工具。 Amazon aws-cli 1.45.28之前版本和AWS CLI v2 2.35.3之前版本存在加密问题漏洞,该漏洞源于EMR SSH helper命令中的密钥交换缺少实体认证,可能导致中间人攻击者通过客户端与EMR集群端点之间的网络定位拦截SSH会话和文件传输。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18733 | 8.8 HIGH | Prompt injection bypasses shell tool consent gate in Strands Agents Tools |
| CVE-2026-18655 | 6.5 MEDIUM | Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt I |
No comments yet