CVE-2025-63604
中文标题:
(暂无数据)
英文标题:
A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows...
漏洞描述
中文描述:
(暂无数据)
英文描述:
A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input validation in the execute_query method. The vulnerability stems from the exposure of dangerous Python built-in functions (__import__, getattr, hasattr) in the execution namespace and the direct use of exec() to execute user-supplied code. An attacker can craft malicious queries to execute arbitrary Python code, leading to AWS credential theft (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY), file system access, environment variable disclosure, and potential system compromise. The vulnerability allows attackers to bypass intended security controls and gain unauthorized access to sensitive AWS resources and credentials stored in the server's environment.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| baryhuang | aws_resources_mcp_server | 0.1.0 | - | - |
cpe:2.3:a:baryhuang:aws_resources_mcp_server:0.1.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (adp)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-63604 |
2025-11-19 04:05:45 | 2026-01-12 02:12:16 |
| NVD | nvd_CVE-2025-63604 |
2026-01-01 04:27:55 | 2026-01-12 02:27:59 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']