Amazon DynamoDB MCP Server <2.1.6: TL Template Exploit
CVE-2026-85654 Published on September 4, 2026

Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-85654 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
ACTIVE

Weakness Type

CWE-1336

Products Associated with CVE-2026-85654

stack.watch emails you whenever new vulnerabilities are published in Amazon Awslabs Dynamodb Mcp Server or Amazon Aws. Just hit a watch button to start following.

 
 

Affected Versions

Amazon awslabs.dynamodb-mcp-server: