Skip to content

MCPA-2026-0011

mediumauth-missing

AWS Labs DocumentDB MCP Server read-only mode bypass via write-capable aggregation pipeline stages (CVE-2026-18954)

awslabs.documentdb-mcp-server before 1.0.12 enforces read-only mode incorrectly in its aggregation pipeline tool: an authenticated MCP client can include write-capable aggregation stages that bypass the read-only enforcement logic and perform inappropriate write operations on the connected DocumentDB database. Fixed in 1.0.12.

Affected packages

EcosystemPackageAffected versions
pypiawslabs.documentdb-mcp-server
>= 0, < 1.0.12

Identifiers

CVE-2026-18954GHSA-w95p-h69m-853rCWE-863

References

Timeline

  • Published: 2026-08-05

← All advisories