CVE-2026-18953: Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server
Improper limitation of a pathname to a restricted directory in the getresource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter.
To remediate this issue, users should upgrade to version 0.1.5 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon awslabs.aws-transform-mcp-serverto a version that resolves this vulnerability.Fixed in 0.1.5