Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 11 min 108 bronnen 2 kritiek 31 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2026-18953

HIGH · 8.6 CVSS Gepubliceerd: CWE-22

Beschrijving

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter.

To remediate this issue, users should upgrade to version 0.1.5 or later.

Vendors

Amazon

Affected products

Aws Transform Mcp Server

References