Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context.
To remediate this issue, users should upgrade to version 1.3.9.
To remediate this issue, users should upgrade to version 1.3.9.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 16 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9. | |
| Title | AWS API MCP File Access Restriction Bypass | |
| Weaknesses | CWE-424 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-03-16T18:17:17.927Z
Reserved: 2026-03-16T14:28:58.998Z
Link: CVE-2026-4270
No data.
Status : Received
Published: 2026-03-16T17:16:32.270
Modified: 2026-03-16T17:16:32.270
Link: CVE-2026-4270
No data.
OpenCVE Enrichment
No data.
Weaknesses