Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-08-05

HighPrimary

AWS Transform MCP Server Path Traversal Lets Tool Calls Write Files Outside the Intended Output Directory

Analysis of CVE-2026-18953, a path traversal flaw in the AWS Transform MCP Server get_resource tool that allowed files to be written outside the intended directory.

AWS Transform MCP ServerTool execution / MCPPath traversal and arbitrary file write through an MCP toolDeveloper workstation running aws-transform-mcp-server versions 0.1.0 through 0.1.4

What happened

A crafted get_resource invocation supplies a traversal path that writes content outside the tool's intended directory.

Why it matters

Unauthorized modification of files reachable by the local MCP server process, with impact depending on its permissions and chosen path.

Missing authorization check

Canonical path enforcement plus action-specific authorization for writes outside the declared workspace.

Would PP block it?

The signed request would bind the allowed output directory and normalized destination. A traversal path resolving elsewhere would fail before the MCP tool executes.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-08-05

    AWS publishes CVE-2026-18953 and releases aws-transform-mcp-server 0.1.5 with the fix.

Technical breakdown

  • The vulnerable get_resource tool accepted a caller-influenced output path.
  • Path handling did not reliably constrain the normalized destination to the intended directory.
  • Traversal sequences could therefore redirect the write to another filesystem location accessible to the process.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
MCP proxy before get_resource execution
Still needs
Host filesystem sandboxing remains a necessary defense in depth control.
Receipt required for
Writing a retrieved transformation artifact to a local filesystem path

A Tool-Call Gate can canonicalize the destination, compare it with the authorized scope, and deny any write outside that scope.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop