SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85654

HIGH · CVSS 7.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The CDK generator in Amazon awslabs.dynamodb-mcp-server versions prior to 2.1.6 is vulnerable due to improper handling of special elements in its template engine, potentially allowing an attacker to execute arbitrary code on the host deploying the application. This vulnerability poses a significant risk, especially for organizations using this tool to manage DynamoDB applications, as it could lead to unauthorized access and control over critical systems. Users of affected versions should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-85654
Severity
HIGH
CVSS
7.8
EPSS
0.14%

Original NVD Description

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.