What happened
AWS published bulletin 2026-121 on 2026-10-01: CVE-2026-97662 (CVSS 8.2) is an argument-injection flaw in the diff-scan operation of security-agent-mcp-server. A crafted reference value is parsed as a CLI flag rather than a revision, breaking the workspace-confinement guard to create/overwrite/truncate arbitrary files on the host.
Why it matters
This is a privilege-confusing MCP tool bug in a security-focused agent: the very tool meant to scan code for vulnerabilities can be hijacked (via prompt injection in the repo being scanned) into arbitrary host-file writes, converting a developer-trusted MCP server into a file-write primitive on the host running the AI coding agent.
Attack vector
A crafted reference value passed to the diff-scan operation is interpreted as a command-line option rather than a revision, letting an actor create, overwrite, or truncate arbitrary files on the host outside the intended workspace, bypassing the server's workspace-confinement control. Triggerable by a prompt-injected agent driving the MCP diff tool.
Affected systems
AWS security-agent-mcp-server >= 0.1.1 and < 0.2.0
Mitigation
Upgrade to security-agent-mcp-server 0.2.0 (AWS bulletin 2026-121-AWS). Until then, run diff scans only against trusted repositories and run the server as a least-privileged user in isolation.