๐Ÿ” CVE Alert

CVE-2026-85012

HIGH 8.0

OS command injection in the Amazon CodeCatalyst blueprints SDK

CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later. No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.

CWE CWE-78
Vendor aws
Product @amazon-codecatalyst/blueprints.blueprint
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for aws @amazon-codecatalyst/blueprints.blueprint

Be the first to know when new high vulnerabilities affecting aws @amazon-codecatalyst/blueprints.blueprint are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

AWS / @amazon-codecatalyst/blueprints.blueprint
0 < 0.3.156

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
npmjs.com: https://www.npmjs.com/package/@amazon-codecatalyst/blueprints.blueprint/v/0.3.156 aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-095-aws/ github.com: https://github.com/aws/codecatalyst-blueprints/security/advisories/GHSA-c7rj-fr2j-64w7