Alexei Ledenev

1 exploit Active since May 2025
CVE-2025-5277 WRITEUP CRITICAL WRITEUP
aws-mcp-server < 1.3.0 - OS Command Injection via Crafted Prompt
aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system.
CVSS 9.6