Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.
History

Mon, 16 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
Description Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.
Title AWS API MCP File Access Restriction Bypass
Weaknesses CWE-424
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-03-16T16:17:11.659Z

Reserved: 2026-03-16T14:28:58.998Z

Link: CVE-2026-4270

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-16T17:16:32.270

Modified: 2026-03-16T17:16:32.270

Link: CVE-2026-4270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.