Arg Injection in AWS security-agent-mcp-server <0.2.0 Diff Scan
CVE-2026-97662 Published on October 1, 2026

Argument injection in the diff scan operation in AWS security-agent-mcp-server allows arbitrary host file creation, overwrite, and truncation outside the intended workspace
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation. To remediate this issue, users should upgrade to version 0.2.0.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-97662 is exploitable with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.

Attack Vector:
LOCAL
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
CHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Types

What is an Argument Injection Vulnerability?

The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

CVE-2026-97662 has been classified to as an Argument Injection vulnerability or weakness.

External Control of File Name or Path

The software allows user input to control or influence paths or file names that are used in filesystem operations.


Affected Versions

AWS security-agent-mcp-server: