aws-mcp has a Command Injection Remote Code Execution Vulnerability
Critical severity
GitHub Reviewed
Published
Apr 11, 2026
to the GitHub Advisory Database
•
Updated Apr 14, 2026
Description
Published by the National Vulnerability Database
Apr 11, 2026
Published to the GitHub Advisory Database
Apr 11, 2026
Last updated
Apr 14, 2026
Reviewed
Apr 14, 2026
aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of the allowed commands list. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the MCP server. Was ZDI-CAN-27969.
References