CVE-2026-85654
Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-1336
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- Amazon awslabs.dynamodb-mcp-server
Weakness type
Related vulnerabilities
- CVE-2026-87021 — Tanium addressed an unauthorized code execution vulnerability in Comply.
- CVE-2026-33387 — Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0
- CVE-2026-75650 — Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)
- CVE-2026-52762 — YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
- CVE-2026-46636 — Twig: Sandbox method allowlist bypass via `Markup` subclass
- CVE-2026-13297 — Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-75036 — Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing
- CVE-2026-82958 — In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the...