top of page
perceptive_background_267k.jpg

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow …

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 22:02:16

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Supply Chain & Dependencies

CVE-2026-18953 is a path traversal vulnerability (CWE-22) affecting Amazon's awslabs.aws-transform-mcp-server Python package versions 0.1.0 through 0.1.4. The flaw exists in the get_resource tool, where improper limitation of a pathname to a restricted directory allows a context-dependent attacker to write arbitrary files outside the intended working directory via the savePath parameter. This could enable unauthorized file writes to sensitive locations on the host system. The vulnerability has been assigned a high criticality rating. Amazon has released a patched version (0.1.5) to address the issue. Users are strongly advised to upgrade to version 0.1.5 or later immediately. The advisory is supported by references from AWS Security Bulletins, GitHub Security Advisories, and PyPI.

Technical details

Mitigation steps:

Affected products:

Amazon awslabs.aws-transform-mcp-server 0.1.0
Amazon awslabs.aws-transform-mcp-server 0.1.1
Amazon awslabs.aws-transform-mcp-server 0.1.2
Amazon awslabs.aws-transform-mcp-server 0.1.3
Amazon awslabs.aws-transform-mcp-server 0.1.4

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page