Amazon MQ MCP Server Credential Exfiltration via Broker Hostname Prompt Injection
highAgentPrompt InjectionA vulnerability in the Amazon MQ MCP Server allows an attacker to use prompt injection to manipulate the broker hostname parameter, redirecting the agent's connection to an attacker-controlled endpoint. This causes RabbitMQ broker credentials or OAuth access tokens to be sent to the attacker instead of the legitimate Amazon MQ broker, without requiring the attacker to be authenticated. Upgrading to version 2.0.24 remediates the flaw.
Updated Aug 4, 2026 · CVSS 6.5