VYPR
Medium severity5.5NVD Advisory· Published Oct 8, 2026

CVE-2026-107332

CVE-2026-107332

Description

Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files.

To mitigate this issue, users should upgrade to version 4.10.0 or later.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.