Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
OS command injection in jsii-diff in AWS jsii
CVE-2026-15895
Description
OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument.
To mitigate this issue, users should upgrade to jsii-diff v1.131.0 or later.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/aws/jsii/releases/tag/v1.131.0mitrerelease-notespatch
- aws.amazon.com/security/security-bulletins/2026-057-aws/mitrevendor-advisory
News mentions
0No linked articles in our index yet.