Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16320 | aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system. |
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 May 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-05-28T13:27:50.584Z
Reserved: 2025-05-27T14:00:54.037Z
Link: CVE-2025-5277
Updated: 2025-05-28T13:27:41.115Z
Status : Deferred
Published: 2025-05-28T14:15:35.827
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-5277
No data.
OpenCVE Enrichment
No data.
EUVD