OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-97662

HIGH · CVSS 8.2 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

An argument injection vulnerability in the diff scan operation of AWS security-agent-mcp-server prior to version 0.2.0 allows threat actors to manipulate file operations, potentially leading to the creation, overwriting, or truncation of arbitrary files outside the designated workspace. Organizations utilizing this software should prioritize upgrading to version 0.2.0 to mitigate the risk of unauthorized file access and manipulation.

CVE
CVE-2026-97662
Severity
HIGH
CVSS
8.2
EPSS
0.14%

Original NVD Description

An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation. To remediate this issue, users should upgrade to version 0.2.0.