Description
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 04 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file. | |
| Title | Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server | |
| First Time appeared |
Amazon
Amazon awslabs.dynamodb-mcp-server |
|
| Weaknesses | CWE-1336 | |
| CPEs | cpe:2.3:a:amazon:awslabs.dynamodb-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon awslabs.dynamodb-mcp-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-04T18:32:24.712Z
Reserved: 2026-09-04T13:13:01.262Z
Link: CVE-2026-85654
No data.
Status : Received
Published: 2026-09-04T18:18:05.977
Modified: 2026-09-04T18:18:05.977
Link: CVE-2026-85654
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine