Security: awslabs/mcp
Security
.github/SECURITY
Reporting a Vulnerability If you discover a potential security issue in this project we ask that you notify AWS/Amazon Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. !!! IMPORTANT !!! Please do not create a GitHub issue, pull request, or other public annoucements.
-
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP ServerGHSA-j694-4m5j-w8hc published
Aug 5, 2026 by scottschreckengaustModerate -
Improper limitation of a pathname in AWS Transform MCP ServerGHSA-66mr-jr63-2jgw published
Aug 5, 2026 by scottschreckengaustHigh -
Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-serverGHSA-6x7f-488g-75wm published
Jul 17, 2026 by scottschreckengaustModerate -
AWS HealthLake MCP Server SSRF via Unvalidated Pagination URLGHSA-c5vr-x62j-w6rw published
Jul 14, 2026 by scottschreckengaustHigh -
Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt InjectionGHSA-xwj6-8x5h-hjp6 published
Aug 3, 2026 by scottschreckengaustModerate -
AWS API MCP Server Security Policy Bypass via Startup Initialization FailureGHSA-29w2-fq35-v728 published
Jul 23, 2026 by arnewoutersHigh -
AWS API MCP File Access Restriction BypassGHSA-2cpp-j2fc-qhp7 published
Mar 16, 2026 by rshevchuk-gitModerate
Learn more about advisories related to awslabs/mcp in the GitHub Advisory Database