Threat · curated 8 Aug 2026
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
First reported · updated · 2 reports amazon.com
Coverage timeline
Why it matters
CVE-2026-18655 shows how prompt injection against an MCP server can leak broker credentials and OAuth tokens, giving attackers access to backend messaging infrastructure through the AI tool-calling layer.
CVE-2026-18655 is a vulnerability in the AWS Labs Amazon MQ MCP Server that allows broker credential and OAuth token disclosure via prompt injection, disclosed in AWS security bulletin 2026-070-AWS and GitHub advisory GHSA-xwj6-8x5h-hjp6. An attacker can use indirect prompt injection against the MCP server to exfiltrate sensitive broker credentials and OAuth tokens.