CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
Amazon DynamoDB ยท 2026-09-09
Actions
Technical Details
| Affected Versions | 2.0.10, 2.1.5 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-85654 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update the DynamoDB MCP server to version 2.1.6 to address the code injection vulnerability (CVE-2026-85654) and ensure the security of generated CDK applications.
For Platform Teams
Deploy the patched DynamoDB MCP server (version 2.1.6) to simplify architecture and reduce operational toil by preventing potential code injection attacks.
For Executives
Implement the security patch for DynamoDB MCP server (version 2.1.6) to mitigate the risk of code injection attacks and protect customer data and applications from potential breaches.
Source
Related Amazon DynamoDB Updates
- CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server (2026-09-04)
- Introducing strands-dynamodb-storage: Durable agent storage for the Strands Agents SDK (2026-09-02)
- Amazon DynamoDB now supports real-time vector search (2026-08-05)
- Amazon DynamoDB now supports real-time vector search at any scale (2026-08-05)
- Announcing General Availability of DynamoDB Mapper for Kotlin (2026-08-03)