VYPR

aws-transform-mcp-server

by Amazon

CVEs (1)

  • CVE-2026-18953Aug 5, 2026
    risk 0.00cvss epss

    Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. …