AWS Security Agent MCP server could hand a scanned workspace's source archive, credentials included, to an attacker-owned S3 bucket
NVD·medium signal
CVE-2026-87913 (CVSS 5.1, published September 10) affects the AWS Security Agent MCP server before 0.2.0. The server never checked who owned its upload bucket, and the bucket name comes from the public account ID. An attacker who registers that bucket name first receives the private source archive, including credentials and infrastructure state. The same NVD window lists CVE-2026-88938 (7.1): the knowns code.find MCP tool, through 0.33.0, reads files anywhere on the host via absolute paths or ../ sequences.