To remediate this issue, users should upgrade to aws-cdk-lib 2.245.0 (2.246.0 on Windows) or later.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 10 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This issue requires the threat actor to control the value of one or more of the affected bundling properties in the CDK application. To remediate this issue, users should upgrade to aws-cdk-lib 2.245.0 (2.246.0 on Windows) or later. | |
| Title | OS Command Injection in NodejsFunction Bundling in aws-cdk-lib | |
| First Time appeared |
Aws
Aws aws Cloud Development Kit Library |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:aws:aws_cloud_development_kit_library:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws Cloud Development Kit Library |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-06-10T18:17:44.552Z
Reserved: 2026-06-05T19:19:07.636Z
Link: CVE-2026-11417
Updated: 2026-06-10T18:17:41.343Z
Status : Awaiting Analysis
Published: 2026-06-10T18:16:39.940
Modified: 2026-06-10T18:35:49.083
Link: CVE-2026-11417
No data.
OpenCVE Enrichment
Updated: 2026-06-10T19:30:37Z