Arg Injection in AWS security-agent-mcp-server <0.2.0 Diff Scan
CVE-2026-97662 Published on October 1, 2026
Argument injection in the diff scan operation in AWS security-agent-mcp-server allows arbitrary host file creation, overwrite, and truncation outside the intended workspace
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan operation.
To remediate this issue, users should upgrade to version 0.2.0.
Vulnerability Analysis
CVE-2026-97662 is exploitable with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.
Weakness Types
What is an Argument Injection Vulnerability?
The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CVE-2026-97662 has been classified to as an Argument Injection vulnerability or weakness.
External Control of File Name or Path
The software allows user input to control or influence paths or file names that are used in filesystem operations.
Affected Versions
AWS security-agent-mcp-server:- Version 0.1.1 and below 0.2.0 is affected.