Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions.



To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Sep 2026 16:30:00 +0000


Fri, 11 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions. To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository.
Title OS command injection in the task synthesis component in projen
First Time appeared Aws
Aws projen
Weaknesses CWE-78
CWE-88
CPEs cpe:2.3:a:aws:projen:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws projen
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-11T16:21:02.834Z

Reserved: 2026-09-10T18:44:43.656Z

Link: CVE-2026-89066

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T16:17:49.400

Modified: 2026-09-11T17:19:31.453

Link: CVE-2026-89066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses