跳到正文
原文
Permission Protocol · AI Agent Incident Tracker·· 2026/08/05AI 评分62

AWS Transform MCP Server 路径穿越漏洞可写入目标目录外文件

原文标题:AWS Transform MCP Server Path Traversal Lets Tool Calls Write Files Outside the Intended Output Directory

AI 导读

AWS 披露 CVE-2026-18953,aws-transform-mcp-server 的 get_resource 工具接受调用方影响的输出路径,路径处理未可靠地把规范化后的目标限制在预期目录内,攻击者可用穿越序列把文件写到进程可访问的其他位置,影响范围取决于该进程的权限和所选路径。

正文

当前语言的正文正在等待翻译,暂时显示原文。

Back to incident tracker

2026-08-05

HighPrimary

AWS Transform MCP Server Path Traversal Lets Tool Calls Write Files Outside the Intended Output Directory

Analysis of CVE-2026-18953, a path traversal flaw in the AWS Transform MCP Server get_resource tool that allowed files to be written outside the intended directory.

AWS Transform MCP ServerTool execution / MCPPath traversal and arbitrary file write through an MCP toolDeveloper workstation running aws-transform-mcp-server versions 0.1.0 through 0.1.4

What happened

A crafted get_resource invocation supplies a traversal path that writes content outside the tool's intended directory.

Why it matters

Unauthorized modification of files reachable by the local MCP server process, with impact depending on its permissions and chosen path.

Missing authorization check

Canonical path enforcement plus action-specific authorization for writes outside the declared workspace.

Would PP block it?

The signed request would bind the allowed output directory and normalized destination. A traversal path resolving elsewhere would fail before the MCP tool executes.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-05

    AWS publishes CVE-2026-18953 and releases aws-transform-mcp-server 0.1.5 with the fix.

Technical breakdown

  • The vulnerable get_resource tool accepted a caller-influenced output path.
  • Path handling did not reliably constrain the normalized destination to the intended directory.
  • Traversal sequences could therefore redirect the write to another filesystem location accessible to the process.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
MCP proxy before get_resource execution
Still needs
Host filesystem sandboxing remains a necessary defense in depth control.
Receipt required for
Writing a retrieved transformation artifact to a local filesystem path

A Tool-Call Gate can canonicalize the destination, compare it with the authorized scope, and deny any write outside that scope.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop

来源:Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com