Impact
The vulnerability is a server‑side request forgery located in the pagination handling component of the AWS HealthLake MCP Server. A remote authenticated user can insert a crafted next_token value that causes the server to issue HTTP requests to an arbitrary external URL. These requests contain the server’s temporary AWS credentials, enabling an attacker to exfiltrate those credentials.
Affected Systems
The affected product is AWS HealthLake MCP Server (awslabs.healthlake-mcp-server). Versions prior to 0.0.14 on all platforms are vulnerable, regardless of operating system or deployment environment.
Risk and Exploitability
The CVSS score of 9.2 indicates high impact. The EPSS score is reported as less than 1 %, suggesting a low probability of exploitation at a global level, but the flaw remains severe because it requires only an authenticated user. The attack does not require privileged network access; the malicious next_token value can be supplied over the network to the vulnerable server, allowing the attacker to cause the server to contact an arbitrary endpoint. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment