VYPR

localstack

by Localstack

CVEs (3)

  • CVE-2021-32090CriMay 7, 2021
    risk 0.57cvss 9.8epss 0.02

    The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.

  • CVE-2021-32091MedMay 7, 2021
    risk 0.40cvss 6.1epss 0.01

    A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6.

  • CVE-2026-16763Jul 23, 2026
    risk 0.00cvss epss 0.01

    A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command…