aws-mcp-server command injection flaws allow unauthenticated remote code execution
Two vulnerabilities (CVE-2026-5058 and CVE-2026-5059) in aws-mcp-server stem from improper validation of user-supplied strings against the allowed commands list before executing system calls, letting remote unauthenticated attackers run arbitrary code in the context of the MCP server.
Disclosed 11 April 2026 · Record updated 13 September 2026
Impact
Remote attackers can execute arbitrary code on affected aws-mcp-server installations without authentication.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-5058
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-5059
