Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w95p-h69m-853r

Опубликовано: 05 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.7
CVSS3: 5.5

Описание

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.

To remediate this issue, users should upgrade to version 1.0.12 or later.

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic.

To remediate this issue, users should upgrade to version 1.0.12 or later.

EPSS

Процентиль: 1%
0.00108
Низкий

5.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.5
nvd
13 дней назад

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To remediate this issue, users should upgrade to version 1.0.12 or later.

EPSS

Процентиль: 1%
0.00108
Низкий

5.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-863