The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade awslabs.aws-api-mcp-server to version 1.3.9 or higher.
awslabs.aws-api-mcp-server is a Model Context Protocol (MCP) server for interacting with AWS
Affected versions of this package are vulnerable to Improper Protection of Alternate Path through the AWS CLI shorthand parser in aws_api_mcp_server/core/aws/services.py. An attacker can read arbitrary local files in the MCP client application context by supplying file:// or fileb:// shorthand parameter values such as @=-style file references, when file access is intended to be disabled or limited to a workdir.