Impact
Improper restriction of intended RabbitMQ broker connection endpoints in the Amazon MQ MCP Server’s broker tools allows a remote, unauthenticated actor to inject a malicious prompt that creates a crafted endpoint. This abuse can lead to the disclosure of broker credentials or OAuth access tokens that are normally sent to a broker hostname. The exposed credentials may then enable full trust access to the RabbitMQ broker and any downstream services relying on these tokens, representing a significant confidentiality breach. The weakness is formally categorized as CWE‑923.
Affected Systems
All installations of AWS Amazon MQ MCP Server with versions older than 2.0.24 are affected. The vulnerability originates in the RabbitMQ broker connection utilities provided by the MCP Server and impacts any system that relies on these utilities for broker authentication.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating high severity, while its EPSS score is not available and it is not listed in CISA’s KEV catalog, suggesting no known active exploitation. A remote, unauthenticated attacker may exploit the flaw by injecting a prompt that causes the MCP client to target a user‑controlled hostname, thereby capturing broker credentials or OAuth tokens transmitted to that endpoint. The lack of authentication and insufficient endpoint restrictions amplify the risk of credential misuse once exposed.
OpenCVE Enrichment