VYPR

Language Servers for AWS

by AWS

Source repositories

CVEs (2)

  • CVE-2026-12958HigJun 23, 2026
    risk 0.44cvss 7.8epss 0.00

    Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust…

  • CVE-2026-12957HigJun 23, 2026
    risk 0.44cvss 7.8epss 0.00

    Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be…