CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server

Amazon Web Services Version 1 original current

Imported from official source

Bulletin ID: 2026-097-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 10:00 AM PDT Description: Amazon awslabs.dynamodb-mcp-server is an open-source Model Context Protocol (MCP) server that enables AI coding assistants to interact with Amazon DynamoDB, including table design, data modeling, and CDK infrastructure generation. …

This version

Version
1 of 1
Recorded
September 18, 2026 09:42
Change
Initial
Content hash
0b9193e0eaf29d0a3ff79839585c6ed8
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.