If you discover a security vulnerability in AWS MCP Server, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
- Email: Send details to the repository maintainer (see GitHub profile)
- GitHub Security Advisory: Use GitHub's private vulnerability reporting
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
For detailed information about the security architecture, command validation, and sandbox execution, see Security Architecture.
| Version | Supported |
|---|---|
| Latest | ✅ |
| < 1.0 | ❌ |
When using AWS MCP Server:
- Use Docker deployment - Provides strongest isolation
- Apply least-privilege IAM - Limit AWS credentials to minimum required permissions
- Keep updated - Use latest version for security fixes
- Review blocked commands - Understand what operations are restricted in strict mode