CVE-2025-5277: Alexei-Led Aws-Mcp-Server

Critical severity, CVSS 9.6. EPSS: 1.2% chance of exploitation in the next 30 days.

aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system.

Affected products

  • Alexei-Led Aws-Mcp-Server: before 1.3.0 (fixed in 1.3.0)

Published 2025-05-28. Last modified 2026-06-17.