Amazon DynamoDB MCP Server <2.1.6: TL Template Exploit
CVE-2026-85654 Published on September 4, 2026
Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.
Vulnerability Analysis
CVE-2026-85654 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Products Associated with CVE-2026-85654
stack.watch emails you whenever new vulnerabilities are published in Amazon Awslabs Dynamodb Mcp Server or Amazon Aws. Just hit a watch button to start following.
Affected Versions
Amazon awslabs.dynamodb-mcp-server:- Version 2.0.10, <= 2.1.5 is affected.