CyberRota Analysis
AI-GeneratedAn argument injection vulnerability in the diff scan operation of AWS security-agent-mcp-server prior to version 0.2.0 allows threat actors to manipulate file operations, potentially leading to the creation, overwriting, or truncation of arbitrary files outside the designated workspace. Organizations utilizing this software should prioritize upgrading to version 0.2.0 to mitigate the risk of unauthorized file access and manipulation.
Original NVD Description
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation. To remediate this issue, users should upgrade to version 0.2.0.