Amazon · Aws-Cdk-Lib · CVE-2026-13760
**Name of the Vulnerable Software and Affected Versions**
aws-cdk-lib versions prior to 2.260.0
**Description**
OS command injection exists in the NodejsFunction Docker bundling pipeline within the OsCommand helper. An actor who can control dependency version strings in a project's package.json file may execute arbitrary commands on the host running the CDK toolchain by injecting shell metacharacters into the OsCommand helper. This occurs during Docker-based bundling when nodeModules are specified.
**Recommendations**
Upgrade to version 2.260.0.