CVE-2026-18655 Details
Description
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. To remediate this issue, users should upgrade to version 2.0.24.
A vulnerability in AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) versions prior to 2.0.24 allows remote unauthenticated actors to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens. This is achieved through prompt injection, where a crafted broker hostname directs these credentials to an endpoint controlled by the actor. The vulnerability arises because the affected version improperly validates the broker_hostname parameter before sending authorization details in HTTPS requests.
Users should upgrade to AWS Amazon MQ MCP Server version 2.0.24 or later. After upgrading, it is recommended to rotate broker credentials. For those using version 2.0.24, the 'broker_hostname' parameter has been replaced with 'broker_id' and 'region' parameters, allowing the server to validate and resolve the correct endpoint through the Amazon MQ DescribeBroker API. Instructions for upgrading and configuring the MCP server are available on the PyPI page for version 2.0.24.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | New CVE Received | AMZN |
| Aug 3, 2026 | CVE Modified | CISA-ADP |