CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server

Bulletin ID: 2026-097-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/04/2026 10:00 AM PDT
Last Updated Date: 09/08/2026 09:45 AM PDT

Amazon awslabs.dynamodb-mcp-server is an open-source Model Context Protocol (MCP) server that enables AI coding assistants to interact with Amazon DynamoDB, including table design, data modeling, and CDK infrastructure generation. We identified CVE-2026-85654, an improper neutralization of special elements used in a template engine in the CDK generator component. Under certain circumstances, a context-dependent actor could execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.

Impacted versions: >= 2.0.10 AND <= 2.1.5

This issue has been addressed in awslabs.dynamodb-mcp-server version 2.1.6. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Users who cannot immediately upgrade should manually review the contents of dynamodb_data_model.json for unexpected or unintended table, index, or attribute names before running the CDK generator. Avoid using data model files from untrusted or unverified sources.

We would like to thank Jaimen Bell for collaborating on this issue through the coordinated vulnerability disclosure process.

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-097-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 18, 2026 09:42
Versions
1 recorded
Identity
54c7a2d9b16d1dc90f5a65c6bdb8a417cfa8fd6e

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.