CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
Summary
A vulnerability exists in AWS Transform MCP Server (a tool that lets AI assistants run code-transformation jobs on a developer's local machine) versions 0.1.0 through 0.1.4. An attacker could exploit improper pathname validation in the get_resource tool to write files anywhere on the system outside the intended directory, potentially leading to local code execution (unauthorized commands running on the developer's computer).
Solution / Mitigation
Update awslabs.aws-transform-mcp-server to version 0.1.5 or later.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-075-aws/
First tracked: August 5, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 92%