High severity7.8NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-15895
CVE-2026-15895
Description
OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument.
To mitigate this issue, users should upgrade to jsii-diff v1.131.0 or later.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jsii-diffnpm | < 1.131.0 | 1.131.0 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-wcx4-wpfv-mc5cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-15895ghsaADVISORY
- aws.amazon.com/security/security-bulletins/2026-057-awsghsaWEB
- github.com/aws/jsii/releases/tag/v1.131.0nvdWEB
- github.com/aws/jsii/security/advisories/GHSA-wcx4-wpfv-mc5cghsaWEB
- aws.amazon.com/security/security-bulletins/2026-057-aws/nvd
News mentions
0No linked articles in our index yet.