Threat · curated 10 Sep 2026

CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server

Coverage timeline

10 Sep 2026amazon.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-85654 lets attackers inject code through an Amazon MCP server, a core connective tissue for AI agents, meaning a compromised tool server can lead to arbitrary code execution in agentic workflows.

CVE-2026-85654 is a code-injection vulnerability in the CDK generator of Amazon's awslabs.dynamodb-mcp-server, disclosed in AWS security bulletin 2026-097-AWS and a corresponding GitHub security advisory (GHSA-35jj-hwvm-792x). The flaw affects an MCP server component used by AI agents to interact with DynamoDB.