CVE-2026-15415 MEDIUM

CVE-2026-15415: Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server

Vendor Aws
Product aws-healthomics-mcp-server
Weakness CWE-23
Published July 17, 2026
Last update July 20, 2026

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a restricted directory in the linting tools of the AWS HealthOmics MCP Server (aws-healthomics-mcp-server) before version 0.0.36 might allow an actor who can influence the MCP agent to write an actor-controlled content to arbitrary locations outside the intended workflow bundle directory, via directory traversal sequences in the workflow_files input. To remediate this issue, users should upgrade to version 0.0.36 or later.

Key dates

02Disclosure timeline

July 17, 2026 CVE published
July 20, 2026 Record updated

Related vulnerabilities

04Related CVE