Impact
A missing verification of the ownership of an S3 bucket in the AWS Security Agent MCP server before version 0.2.0 permits an attacker to read the private source archive of a scanned workspace. The archive contains credentials and infrastructure state, which could be exfiltrated by the attacker.
Affected Systems
The vulnerability affects the AWS Security Agent MCP server, specifically all releases prior to 0.2.0.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited. Attackers can target a pre‑registered storage bucket whose name is derived from a publicly known account identifier, thereby obtaining confidential data. While the risk is moderate, the potential for exposing sensitive assets warrants prompt remediation.
OpenCVE Enrichment