PT-2026-64183 · Localstack · Serverless-Localstack

·

CVE-2026-16763

·

Published

2026-07-23

·

Updated

2026-07-24

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions localstack serverless-localstack versions prior to 1.4.1
Description An OS command injection issue exists within the Configuration Handler component in the src/index.js file. This occurs when the custom.localstack.docker.compose file argument is manipulated, allowing for the execution of arbitrary operating system commands. This issue requires local access to be exploited.
Recommendations Update localstack serverless-localstack to a version newer than 1.4.0. Avoid using the custom.localstack.docker.compose file argument until the software is updated.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16763

Affected Products

Serverless-Localstack