CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
Transform Mcp ยท 2026-09-09
Actions
Technical Details
| Affected Versions | 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18953 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update awslabs.aws-transform-mcp-server to version 0.1.5 to address the security vulnerability CVE-2026-18953 and prevent arbitrary file writes outside the intended directory.
For Platform Teams
Deploy the latest version of awslabs.aws-transform-mcp-server to ensure security compliance and protect against potential local code execution vulnerabilities.
For Executives
Implement the upgrade to awslabs.aws-transform-mcp-server version 0.1.5 to mitigate the risk of local code execution due to improper pathname limitation.