AWS Transform MCP Server 路径穿越漏洞可写入目标目录外文件
原文标题:AWS Transform MCP Server Path Traversal Lets Tool Calls Write Files Outside the Intended Output Directory
AWS 披露 CVE-2026-18953,aws-transform-mcp-server 的 get_resource 工具接受调用方影响的输出路径,路径处理未可靠地把规范化后的目标限制在预期目录内,攻击者可用穿越序列把文件写到进程可访问的其他位置,影响范围取决于该进程的权限和所选路径。
当前语言的正文正在等待翻译,暂时显示原文。
2026-08-05
HighPrimary
AWS Transform MCP Server Path Traversal Lets Tool Calls Write Files Outside the Intended Output Directory
Analysis of CVE-2026-18953, a path traversal flaw in the AWS Transform MCP Server get_resource tool that allowed files to be written outside the intended directory.
AWS Transform MCP ServerTool execution / MCPPath traversal and arbitrary file write through an MCP toolDeveloper workstation running aws-transform-mcp-server versions 0.1.0 through 0.1.4
What happened
A crafted get_resource invocation supplies a traversal path that writes content outside the tool's intended directory.
Why it matters
Unauthorized modification of files reachable by the local MCP server process, with impact depending on its permissions and chosen path.
Missing authorization check
Canonical path enforcement plus action-specific authorization for writes outside the declared workspace.
Would PP block it?
The signed request would bind the allowed output directory and normalized destination. A traversal path resolving elsewhere would fail before the MCP tool executes.
Incident analysis
Timeline and technical read
Timeline
2026-08-05
AWS publishes CVE-2026-18953 and releases aws-transform-mcp-server 0.1.5 with the fix.
Technical breakdown
- The vulnerable get_resource tool accepted a caller-influenced output path.
- Path handling did not reliably constrain the normalized destination to the intended directory.
- Traversal sequences could therefore redirect the write to another filesystem location accessible to the process.
Authorization boundary
Where the authorization boundary should have been
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
- If enforced at
- MCP proxy before get_resource execution
- Still needs
- Host filesystem sandboxing remains a necessary defense in depth control.
- Receipt required for
- Writing a retrieved transformation artifact to a local filesystem path
A Tool-Call Gate can canonicalize the destination, compare it with the authorized scope, and deny any write outside that scope.
Start small
Put the relevant gate at this action boundary.
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.
来源:Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com