Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mostafa Ashraf

#40252of 56,330
7.3Total CVSS
Vulnerabilities · 1
PT-2026-54636
7.3
2026-07-01
Amazon · Aws-Cdk-Lib · CVE-2026-13760
**Name of the Vulnerable Software and Affected Versions** aws-cdk-lib versions prior to 2.260.0 **Description** OS command injection exists in the NodejsFunction Docker bundling pipeline within the OsCommand helper. An actor who can control dependency version strings in a project's package.json file may execute arbitrary commands on the host running the CDK toolchain by injecting shell metacharacters into the OsCommand helper. This occurs during Docker-based bundling when nodeModules are specified. **Recommendations** Upgrade to version 2.260.0.