CVE-2026-4270 identifies an Improper Protection of Alternate Path vulnerability (CWE-424) in AWS API MCP Server versions 0.2.14 through 1.3.8. This flaw allows for the bypass of file access restrictions within the `no-access` and `workdir` features, potentially exposing arbitrary local file contents in the MCP client application context. Rated with a CVSS score of 5.5 (Medium), exploitation requires local access and user interaction (AV:L/UI:R) but has low attack complexity (AC:L), resulting in a high impact on confidentiality (C:H). Currently, there is no evidence of active exploitation, nor are public exploit modules available. Community discussion and media coverage remain minimal, and it is not listed on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.2.14, < 1.3.9CPE match | cpe:2.3:a:amazon:aws_api_mcp_server:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.