THREAT OPS › Threat News › [GHSA] GHSA-hqvf-45jj-mccq (medium) — AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
[GHSA] GHSA-hqvf-45jj-mccq (medium) — AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
GHSA-hqvf-45jj-mccq Severity: medium CVE: CVE-2026-18654
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
### Summary The AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. An issue exists where the EMR SSH helper commands (`aws emr ssh`, `aws emr socks`, `aws emr put`, `aws emr get`) passed `StrictHostKeyChecking
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-18654cve
Original source: https://github.com/advisories/GHSA-hqvf-45jj-mccq