Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file. | |
| Title | Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server | |
| First Time appeared |
Amazon
Amazon awslabs.dynamodb-mcp-server |
|
| Weaknesses | CWE-1336 | |
| CPEs | cpe:2.3:a:amazon:awslabs.dynamodb-mcp-server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon awslabs.dynamodb-mcp-server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-04T18:32:24.712Z
Reserved: 2026-09-04T13:13:01.262Z
Link: CVE-2026-85654
No data.
Status : Received
Published: 2026-09-04T18:18:05.977
Modified: 2026-09-04T18:18:05.977
Link: CVE-2026-85654
No data.
OpenCVE Enrichment
No data.
-
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine