CVE-2026-18655: Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context.
To remediate this issue, users should upgrade to version 2.0.24.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
awslabs.amazon-mq-mcp-serverto a version that resolves this vulnerability.Fixed in 2.0.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18655?
The severity of CVE-2026-18655 is classified as medium with a score of 6.5.
How do I fix CVE-2026-18655?
To fix CVE-2026-18655, upgrade the awslabs.amazon-mq-mcp-server software to version 2.0.24 or later.
What are the potential impacts of CVE-2026-18655?
CVE-2026-18655 may allow a remote unauthenticated actor to access Amazon MQ for RabbitMQ broker credentials or OAuth access tokens.
What type of vulnerability is CVE-2026-18655?
CVE-2026-18655 is a prompt injection vulnerability that leads to credential disclosure.
Which software is affected by CVE-2026-18655?
CVE-2026-18655 affects the awslabs.amazon-mq-mcp-server software prior to version 2.0.24.