Amazon Web Services has published security advisory 2026-121-AWS documenting an argument injection vulnerability, CVE-2026-97662, in its open-source security-agent-mcp-server. The tool implements the emerging Model Context Protocol (MCP) standard, enabling autonomous AI code-review agents and IDE extensions to query security diffs. Flawed parameter parsing in the repository diff scan handler enables an attacker to supply leading hyphens that are treated as command flags by underlying version control binaries, breaking directory confinement.
Argument Injection Breakdown (CWE-88)
The Model Context Protocol establishes standardized JSON-RPC communication between LLM client applications and backend tools. In security-agent-mcp-server, the diff tool allows an LLM agent to inspect changes between two Git revisions:
// MCP Tool Request
{
"method": "tools/call",
"params": {
"name": "diff",
"arguments": {
"base": "main",
"target": "--output=/path/to/target/file"
}
}
}
Because the server passed the user-supplied target parameter directly into the git diff invocation without preceding positional argument delimiters (such as --), Git interpreted flags such as --output as command options. An attacker manipulating the target branch reference in a pull request could force the Git process to overwrite, create, or truncate critical files within the host environment.
Impact on AI Coding Assistants & CI/CD Pipelines
MCP servers are frequently deployed within developer environments (Cursor, Claude Desktop, VS Code) or integrated directly into CI/CD runners performing automated pull-request triage. Overwriting configuration files (such as .bashrc, authorized_keys, or project manifests) paves the way for lateral escalation into production deployment pipelines.
Remediation Guidance
AWS recommends immediate migration to the patched release:
- Upgrade Package: Update
security-agent-mcp-serverto version 0.2.0 or later:pip install --upgrade security-agent-mcp-server>=0.2.0 - Least-Privilege Execution: Run all local MCP server daemons as a dedicated unprivileged user inside containerized or sandbox boundaries with read-only access to host root file systems.
- Branch Name Sanitization: Verify that CI/CD workflows enforce strict regex validation on branch and revision names (e.g.,
^[a-zA-Z0-9._/-]+$) before passing parameters to code inspection tooling.



