CVE-2026-4270: AWS API MCP Server file access restriction bypass
A flaw in the no-access and workdir features of the AWS API MCP Server (versions >= 0.2.14 and < 1.3.9) allowed intended file access restrictions to be bypassed, exposing arbitrary local file contents in the MCP client application context. AWS published a security bulletin and fixed the issue in version 1.3.9.
Disclosed 16 March 2026 · Record updated 13 September 2026
Impact
Bypass of intended file access restrictions could expose arbitrary local file contents to the MCP client application context.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-4270
