Amazon Open source MCP servers for AWS是美国Amazon公司的一款亚马逊云服务连接的模块集合。 Amazon Open source MCP servers for AWS 2.0.24之前版本存在授权问题漏洞,该漏洞源于对预期端点限制不当,可能导致远程未认证攻击者通过提示注入获取发送到由MCP客户端上下文中broker主机名控制的特制端点的Amazon MQ for RabbitMQ broker凭据或OAuth访问令牌。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | amazon-mq-mcp-server | ≤ 2.0.23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | amazon-mq-mcp-server | 0 ~ 2.0.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18733 | 8.8 HIGH | Prompt injection bypasses shell tool consent gate in Strands Agents Tools |
| CVE-2026-18654 | 6.8 MEDIUM | Disabled SSH host key verification in Amazon AWS CLI EMR helper commands |
No comments yet