Medium severity5.5NVD Advisory· Published Oct 8, 2026
CVE-2026-107332
CVE-2026-107332
Description
Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files.
To mitigate this issue, users should upgrade to version 4.10.0 or later.
Affected products
1- Range: <4.10.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.