๐Ÿ” CVE Alert

CVE-2026-11417

HIGH 7.3

OS Command Injection in NodejsFunction Bundling in aws-cdk-lib

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This issue requires the threat actor to control the value of one or more of the affected bundling properties in the CDK application. To remediate this issue, users should upgrade to aws-cdk-lib 2.245.0 (2.246.0 on Windows) or later.

CWE CWE-78
Vendor aws
Product aws cloud development kit library
Published Jun 10, 2026
Last Updated Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for aws aws cloud development kit library

Be the first to know when new high vulnerabilities affecting aws aws cloud development kit library are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

AWS / AWS Cloud Development Kit library
0 < 2.245.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/aws/aws-cdk/releases/tag/v2.245.0 aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-041-aws/ github.com: https://github.com/aws/aws-cdk/security/advisories/GHSA-999r-qq7v-r334