Impact
The vulnerability in the get_resource tool of Amazon awslabs.aws-transform-mcp-server is an improper limitation of a pathname to a restricted directory. An actor who can influence the savePath parameter can write files to locations outside the intended working directory. The flaw is a classic directory traversal vulnerability (CWE-22) that could allow the attacker to overwrite configuration files, inject malicious code, or otherwise compromise system integrity.
Affected Systems
Affected systems include AWS’s aws-transform-mcp-server product. Versions from 0.1.0 through 0.1.4 are vulnerable and have been patched in 0.1.5 and later releases. No other vendors or product versions are mentioned.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not yet tracked in CISA’s KEV catalog. The description states that a context-dependent actor might exploit it, implying that successful exploitation requires the ability to invoke the get_resource tool. While the precise attack surface is ambiguous, the ability to write arbitrary files could lead to substantial compromise if the attacker can control the payload.
OpenCVE Enrichment