Medium severity5.5NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026
CVE-2026-107608
CVE-2026-107608
Description
Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset.
To remediate this issue, users should upgrade to version 2.267.0 or later.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.267.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.