


Perceptive Security
SOC/SIEM Consultancy

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow …
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 22:02:16
Source:
nvd.nist.gov
Cloud & Virtualization, Supply Chain & Dependencies
CVE-2026-18953 is a path traversal vulnerability (CWE-22) affecting Amazon's awslabs.aws-transform-mcp-server Python package versions 0.1.0 through 0.1.4. The flaw exists in the get_resource tool, where improper limitation of a pathname to a restricted directory allows a context-dependent attacker to write arbitrary files outside the intended working directory via the savePath parameter. This could enable unauthorized file writes to sensitive locations on the host system. The vulnerability has been assigned a high criticality rating. Amazon has released a patched version (0.1.5) to address the issue. Users are strongly advised to upgrade to version 0.1.5 or later immediately. The advisory is supported by references from AWS Security Bulletins, GitHub Security Advisories, and PyPI.
Technical details
Mitigation steps:
Affected products:
Amazon awslabs.aws-transform-mcp-server 0.1.0
Amazon awslabs.aws-transform-mcp-server 0.1.1
Amazon awslabs.aws-transform-mcp-server 0.1.2
Amazon awslabs.aws-transform-mcp-server 0.1.3
Amazon awslabs.aws-transform-mcp-server 0.1.4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18953
https://aws.amazon.com/security/security-bulletins/2026-075-aws/
https://github.com/awslabs/mcp/security/advisories/GHSA-66mr-jr63-2jgw
https://pypi.org/project/awslabs.aws-transform-mcp-server/0.1.5/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
