What is CVE-2026-18953?
CVE-2026-18953 is a path traversal vulnerability in the 'get_resource' tool of 'Amazon awslabs.aws-transform-mcp-server' versions 0.1.0 through 0.1.4. It may allow a context-dependent actor to write arbitrary files outside the intended working directory via the 'savePath' parameter. Immediate remediation involves updating to the latest patched version.
Azərbaycanca: CVE-2026-18953, 'Amazon awslabs.aws-transform-mcp-server'in 0.1.4-ə qədər versiyalarında 'get_resource' alətində 'path traversal' zəifliyidir. Bu, 'savePath' parametri vasitəsilə kontekstdən asılı bir aktyorun nəzərdə tutulan iş qovluğundan kənarda ixtiyari fayllar yazmasına imkan verə bilər. Anında serveri ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What product is affected by CVE-2026-18953?
CVE-2026-18953 affects the 'Amazon awslabs.aws-transform-mcp-server' in versions up to 0.1.4.
What is the recommended remediation for CVE-2026-18953?
Immediate remediation for this vulnerability involves updating the server to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.