To remediate this issue, users should upgrade to aws-cdk-lib 2.245.0 (2.246.0 on Windows) or later.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-999r-qq7v-r334 | aws-cdk-lib: OS Command Injection in NodejsFunction Bundling |
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon aws Cloud Development Kit |
|
| Vendors & Products |
Amazon
Amazon aws Cloud Development Kit |
Wed, 10 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This issue requires the threat actor to control the value of one or more of the affected bundling properties in the CDK application. To remediate this issue, users should upgrade to aws-cdk-lib 2.245.0 (2.246.0 on Windows) or later. | |
| Title | OS Command Injection in NodejsFunction Bundling in aws-cdk-lib | |
| First Time appeared |
Aws
Aws aws Cloud Development Kit Library |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:aws:aws_cloud_development_kit_library:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws Cloud Development Kit Library |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-06-10T18:17:44.552Z
Reserved: 2026-06-05T19:19:07.636Z
Link: CVE-2026-11417
Updated: 2026-06-10T18:17:41.343Z
Status : Awaiting Analysis
Published: 2026-06-10T18:16:39.940
Modified: 2026-06-10T18:35:49.083
Link: CVE-2026-11417
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:41:07Z
Github GHSA