CVE-2026-4270 Details
Description
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.
A vulnerability exists in the AWS API MCP Server's file access management, specifically in versions 0.2.14 and 1.3.9. This vulnerability allows users to bypass intended file access restrictions, potentially exposing arbitrary local file contents within the context of the MCP client application. The issue arises from improper protection of alternate paths in the no-access and workdir features, which can be exploited to access files outside the designated working directory.
Users are advised to upgrade to AWS API MCP Server version 1.3.9 or later. Instructions for upgrading are available on the AWS API MCP Server PyPI page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-007-AWS/ | AMZN | Vendor Advisory |
| https://pypi.org/project/awslabs.aws-api-mcp-server/1.3.9/ | AMZN | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-424 | Improper Protection of Alternate Path | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon aws api mcp server | >= 0.2.14, < 1.3.9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | Initial Analysis | [email protected] |
| Mar 16, 2026 | New CVE Received | AMZN |