This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 24d
MCP SaaS Integrations
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
aws
mcp
mcp-client
mcp-clients
mcp-host
mcp-server
+3 more
mcp-servers
mcp-tools
modelcontextprotocol
Affected surfaces
auth
rbac
Summary
AI summaryUpdates 2026.07.20260702161703, valkey-mcp-server, and billing-cost-management across a mixed release.
Full changelog
2026.07.20260702161703
What's Changed
- fix(billing-cost-management-mcp-server): make getCostCategories honor cost_category_name by @wangyuhere in https://github.com/awslabs/mcp/pull/4031
- docs(aws-knowledge-mcp-server): remove recommend tool from README by @deepankanbn in https://github.com/awslabs/mcp/pull/4042
- feat: Troubleshooting setup for AWS Transform by @aishsun2701 in https://github.com/awslabs/mcp/pull/4028
- feat(healthomics): adds support for scratch storage modes by @markjschreiber in https://github.com/awslabs/mcp/pull/4041
- fix(storage-lens): Validate user queries are read-only SELECT by @Comusus in https://github.com/awslabs/mcp/pull/4030
- feat(valkey-mcp-server): V2 — GLIDE migration, Focused Search + JSON + Command Runner Tools by @Jonathan-Improving in https://github.com/awslabs/mcp/pull/4024
- fix(mysql-mcp-server): close read-only bypasses (CWE-184) and add security-model docs by @happycupofjava in https://github.com/awslabs/mcp/pull/4044
- fix(billing-cost-management): fix SQL-offload and pagination paths for Cost Explorer operations by @wangyuhere in https://github.com/awslabs/mcp/pull/4039
- fix(aws-dataprocessing-mcp-server): block UNLOAD bypass of read-only … by @LiyuanLD in https://github.com/awslabs/mcp/pull/4045
- docs(aurora-dsql): mirror 8 reference files from agent-plugins into skill + Kiro power by @amaksimo in https://github.com/awslabs/mcp/pull/4020
- fix(valkey-mcp-server): use absolute URL for ELASTICACHECONNECT.md link by @Jonathan-Improving in https://github.com/awslabs/mcp/pull/4057
- chore(billing-cost-management): bump version to 0.0.25 by @somsubhro in https://github.com/awslabs/mcp/pull/4069
- chore: release/2026.07.20260702161703 by @awslabs-mcp in https://github.com/awslabs/mcp/pull/4071
New Contributors
- @aishsun2701 made their first contribution in https://github.com/awslabs/mcp/pull/4028
- @Comusus made their first contribution in https://github.com/awslabs/mcp/pull/4030
- @Jonathan-Improving made their first contribution in https://github.com/awslabs/mcp/pull/4024
Full Changelog: https://github.com/awslabs/mcp/compare/2026.06.20260625003520...2026.07.20260702161703
Security Fixes
- mysql-mcp-server fixes read‑only bypass (CWE-184) and adds security-model documentation
- aws-dataprocessing-mcp-server blocks UNLOAD bypass of read‑only mode
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]