VYPR

mcp

by AWS

CVEs (2)

  • CVE-2026-16584HigJul 23, 2026
    risk 0.39cvss 7.0epss 0.00

    Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy…

  • CVE-2026-87913MedSep 10, 2026
    risk 0.38cvss 5.9epss 0.00

    A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a…