Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

aws-mcp-server command injection flaws allow unauthenticated remote code execution

Two vulnerabilities (CVE-2026-5058 and CVE-2026-5059) in aws-mcp-server stem from improper validation of user-supplied strings against the allowed commands list before executing system calls, letting remote unauthenticated attackers run arbitrary code in the context of the MCP server.

Disclosed 11 April 2026 · Record updated 13 September 2026

Impact

Remote attackers can execute arbitrary code on affected aws-mcp-server installations without authentication.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-5058
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-5059