Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Multiple vulnerabilities in Amazon AWS Labs MCP servers

Three vulnerabilities discovered in Amazon awslabs MCP server products: template injection in dynamodb-mcp-server, SQL injection in postgres-mcp-server, and OS command injection via COPY TO PROGRAM statement. Additionally, a supply chain issue in Kiro IDE allows remote actors to redirect registry requests and exfiltrate workspace data.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Template injection in CDK generator allows arbitrary code execution during application deployment; SQL validation bypass allows data modification beyond read-only scope; OS command injection via PostgreSQL COPY statement allows command execution on self-managed servers; supply chain attack via Kiro IDE can exfiltrate workspace credentials.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-hh4r-pcm9-jh93
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-85787
  3. github.comhttps://github.com/advisories/GHSA-f4f4-39r8-8gj4
  4. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-87911
  5. github.comhttps://github.com/advisories/GHSA-gpq4-73r8-h3fj