AWS security-agent-mcp-server 在 0.2.0 版本之前,其 diff scan(差异扫描)操作中存在参数注入漏洞。该漏洞可能允许上下文相关的威胁行为者通过向 diff scan 操作提供精心构造的引用值,在主机上创建、覆盖或截断目标工作区目录之外的任意文件。 为修复此问题,用户应升级至 0.2.0 版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | security-agent-mcp-server | 0.1.1< 0.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | security-agent-mcp-server | 0.1.1 ~ 0.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103505 | 6.5 MEDIUM | AWS EFS CSI Driver Mount Option Injection via mounttargetipmap |
| CVE-2026-104002 | 5.3 MEDIUM | Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python) |
No comments yet