Impact
AWS HealthOmics MCP Server allowed an attacker that can influence the MCP agent to use directory traversal sequences in workflow_files inputs to write arbitrary files outside the intended workflow bundle directory, potentially overwriting critical configuration or secret data. This flaw permits arbitrary file overwrite, compromising integrity and confidentiality of the system and its data.
Affected Systems
AWS HealthOmics MCP Server versions earlier than 0.0.36 are affected; users must upgrade to 0.0.36 or later to eliminate the vulnerability.
Risk and Exploitability
The CVSS score of 6.8 classifies the vulnerability as moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an MCP agent to supply malicious workflow_files inputs; such an actor could be a disgruntled insider or a compromised service using the agent. The exploit requires local or privileged access to the MCP agent process, not a purely remote network attack. Executing the traversal strings allows the attacker to write arbitrary content to any location they can reach, bypassing the intended directory restrictions and potentially compromising the environment.
OpenCVE Enrichment