CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
Mq Mcp ยท 2026-08-20
Actions
Technical Details
| Affected Versions | <= 2.0.23 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18655 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update awslabs.amazon-mq-mcp-server to version 2.0.24 and rotate broker credentials to address CVE-2026-18655, ensuring that your deployments are secure from potential credential and token disclosure vulnerabilities.
For Platform Teams
Deploy the latest version of awslabs.amazon-mq-mcp-server and integrate credential rotation practices to enhance the security posture of your message broker environment.
For Executives
Implement the upgrade to awslabs.amazon-mq-mcp-server version 2.0.24 to mitigate the risk of broker credential and OAuth token disclosure, ensuring the security and integrity of your message broker interactions.