CyberRota Analysis
AI-GeneratedAWS HealthOmics MCP Server versions prior to 0.0.36 are vulnerable to a directory traversal attack, allowing an unauthorized actor to write files to arbitrary locations outside the designated workflow bundle directory. This could lead to potential data manipulation or unauthorized access to sensitive information, impacting organizations utilizing this service for bioinformatics analyses. Users of AWS HealthOmics should prioritize upgrading to version 0.0.36 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a restricted directory in the linting tools of the AWS HealthOmics MCP Server (aws-healthomics-mcp-server) before version 0.0.36 might allow an actor who can influence the MCP agent to write an actor-controlled content to arbitrary locations outside the intended workflow bundle directory, via directory traversal sequences in the workflow_files input. To remediate this issue, users should upgrade to version 0.0.36 or later.