VYPR
Medium severity5.5NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026

CVE-2026-107608

CVE-2026-107608

Description

Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset.

To remediate this issue, users should upgrade to version 2.267.0 or later.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.