Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3549
  • PyPI/awslabs-aws-api-mcp-server
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure 04 Aug
  • Fix available
  • Severity - 7.3 (High)
GHSA-29w2-fq35-v728
  • PyPI/awslabs-aws-api-mcp-server
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure 24 Jul
  • Fix available
  • Severity - 7.3 (High)
GHSA-464c-974j-9xm6
  • Go/github.com/aws/aws-cdk-go/awscdk
  • Go/github.com/aws/aws-cdk-go/awscdk/v2
  • Maven/software.amazon.awscdk:aws-cdk-lib
  • Maven/software.amazon.awscdk:codebuild
  • NuGet/Amazon.CDK.AWS.CodeBuild
  • ... 5 more
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion 24 Jul
  • Fix available
  • Severity - 3.3 (Low)
PYSEC-2026-2387
  • PyPI/aws-encryption-sdk
AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache 13 Jul
  • Fix available
  • Severity - 5.7 (Medium)
PYSEC-2026-1205
  • PyPI/aws-advanced-python-wrapper
AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance 07 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-1206
  • PyPI/aws-sam-cli
AWS SAM CLI Path Traversal allows file copy to local cache 07 Jul
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-1207
  • PyPI/aws-sam-cli
AWS SAM CLI Path Traversal allows file copy to build container 07 Jul
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-288
  • PyPI/aws-mcp
aws-mcp has a Command Injection Remote Code Execution Vulnerability 29 Jun
  • No fix available
  • Severity - 9.8 (Critical)
GHSA-v638-38fc-rhfv
  • PyPI/aws-encryption-sdk
AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache 24 Apr
  • Fix available
  • Severity - 5.7 (Medium)
GHSA-fgmx-xfp3-w28p
  • PyPI/aws-mcp
aws-mcp has a Command Injection Remote Code Execution Vulnerability 11 Apr
  • No fix available
  • Severity - 9.8 (Critical)
GHSA-2cpp-j2fc-qhp7
  • PyPI/awslabs-aws-api-mcp-server
AWS API MCP File Access Restriction Bypass 17 Mar
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-162
  • PyPI/awslabs-aws-api-mcp-server
See record for full details 16 Mar
  • Fix available
  • Severity - 6.8 (Medium)
MAL-2025-191686
  • PyPI/aws-enumerateiam
Malicious code in aws-enumerateiam (PyPI) 18 Nov 2025
  • No fix available
GHSA-4jvf-wx3f-2x8q
  • PyPI/aws-advanced-python-wrapper
AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance 13 Nov 2025
  • Fix available
  • Severity - 8.6 (High)
MAL-2025-41621
  • PyPI/aws-enumerate
Malicious code in aws-enumerate (PyPI) 12 Aug 2025
  • No fix available
GHSA-pp64-wj43-xqcr
  • PyPI/aws-sam-cli
AWS SAM CLI Path Traversal allows file copy to local cache 31 Mar 2025
  • Fix available
  • Severity - 6.9 (Medium)