CVE-2026-4270
AWS API MCP File Access Restriction Bypass
5.5
MEDIUM
CVSS 3.1
EPSS 0.02%
Description
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.
How to fix CVE-2026-4270
To remediate CVE-2026-4270, upgrade the affected package to a fixed version below.
- —upgrade to 1.3.9 or later
- —upgrade to 1.3.9 or later
Is CVE-2026-4270 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 0.2.14, < 1.3.9
- >= 0.2.14, < 1.3.9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |