CVE-2026-18953: Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server
Improper limitation of a pathname to a restricted directory in the getresource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter.
To remediate this issue, users should upgrade to version 0.1.5 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon awslabs.aws-transform-mcp-serverto a version that resolves this vulnerability.Fixed in 0.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18953?
The severity of CVE-2026-18953 is high with a score of 8.6.
How do I fix CVE-2026-18953?
To fix CVE-2026-18953, upgrade the aws-transform-mcp-server package to version 0.1.5 or higher.
What impact does CVE-2026-18953 have on my system?
CVE-2026-18953 may allow an attacker to write arbitrary files outside the intended working directory, leading to potential data loss or system compromise.
Is CVE-2026-18953 related to path traversal vulnerabilities?
Yes, CVE-2026-18953 is classified as a path traversal vulnerability.
Which versions of aws-transform-mcp-server are affected by CVE-2026-18953?
CVE-2026-18953 affects versions 0.1.0 through 0.1.4 of aws-transform-mcp-server.