What happened
A crafted get_resource invocation supplies a traversal path that writes content outside the tool's intended directory.
2026-08-05
HighPrimaryAnalysis of CVE-2026-18953, a path traversal flaw in the AWS Transform MCP Server get_resource tool that allowed files to be written outside the intended directory.
What happened
A crafted get_resource invocation supplies a traversal path that writes content outside the tool's intended directory.
Why it matters
Unauthorized modification of files reachable by the local MCP server process, with impact depending on its permissions and chosen path.
Missing authorization check
Canonical path enforcement plus action-specific authorization for writes outside the declared workspace.
Would PP block it?
The signed request would bind the allowed output directory and normalized destination. A traversal path resolving elsewhere would fail before the MCP tool executes.
Incident analysis
2026-08-05
AWS publishes CVE-2026-18953 and releases aws-transform-mcp-server 0.1.5 with the fix.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
A Tool-Call Gate can canonicalize the destination, compare it with the authorized scope, and deny any write outside that scope.
Related incidents and controls
Framelink Figma MCP Server Passed Unsanitized Input to child_process.exec Enabling Prompt Injection RCE (CVE-2025-53967, CVSS 7.5)
Anthropic Filesystem MCP Server: Symlink Escape and Path Traversal Allow Full Host Filesystem Access (CVE-2025-53109/53110)
Anthropic MCP Inspector Accepted Unauthenticated Connections Leading to CSRF-Chained RCE (CVE-2025-49596, CVSS 9.4)
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.