Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan

AWS identified a security issue in security-agent-mcp-server, an open-source tool used by AI assistants for scanning source code. A specially crafted input in the differential scan function can be mistakenly treated as a command option, allowing an attacker to write or overwrite files outside the intended area, circumventing protections. AWS fixed this in version 0.2.0 and advises upgrading to this version to secure your environment.

QCS published 5/10/2026, 12:19:12 am ISTVendor disclosure 1/10/2026, 11:46:35 pm ISTVerified 5/10/2026, 12:19:12 am ISTRevision 1

In plain language

What this advisory means

AWS identified a security issue in security-agent-mcp-server, an open-source tool used by AI assistants for scanning source code. A specially crafted input in the differential scan function can be mistakenly treated as a command option, allowing an attacker to write or overwrite files outside the intended area, circumventing protections. AWS fixed this in version 0.2.0 and advises upgrading to this version to secure your environment.

Technical explanation

How the issue affects the environment

The vulnerability CVE-2026-97662 exists in the diff scan operation of security-agent-mcp-server, where a crafted reference value supplied to the scan is parsed as a command-line option instead of a revision identifier. This argument injection allows an attacker with context-dependent access to execute unintended commands that can create, overwrite, or truncate arbitrary files on the host system beyond the configured workspace directory, bypassing workspace confinement mechanisms. The flaw affects versions 0.1.1 and later, and was addressed in version 0.2.0 by correcting input handling to prevent option injection.

Operational impact

Why teams should care

This flaw enables an attacker to modify or erase arbitrary files on the host machine, which may lead to corruption of essential files, deployment of malicious code, or disruption of security operations. Such unauthorized file modifications can compromise the integrity of development and production systems, potentially causing data loss, service downtime, or breach of compliance requirements.

Immediate action

Upgrade security-agent-mcp-server to version 0.2.0 or later. Ensure any forks or derivative software also incorporate the fix. After upgrading, verify that the vulnerability is mitigated and that the software runs as expected.

Affected and fixed releases

Affected versions>= 0.1.1
Fixed versions0.2.0

Temporary risk reduction

There is no effective workaround other than upgrading. Until upgrading, only run differential scans on trusted repositories and operate the server process with least privilege in an isolated environment to reduce risk of unauthorized host file modifications.

Evidence and validation checklist

  • Official AWS Security Bulletin publication dated 10/01/2026
  • Description of argument injection vulnerability in diff scan operation
  • Identification of impacted versions (>= 0.1.1)
  • Recommendation and release of fixed version 0.2.0
  • Advice on temporary mitigations prior to upgrade

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source