cve/2025/CVE-2025-5277.md
2025-09-29 21:09:30 +02:00

772 B

CVE-2025-5277

Description

aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system.

POC

Reference

Github