VYPR

aws-cdk-lib

by AWS

CVEs (1)

  • CVE-2026-11417HigJun 10, 2026
    risk 0.40cvss 7.3epss

    OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary…