VYPR

jsii-diff

by AWS

CVEs (1)

  • CVE-2026-15895HigJul 15, 2026
    risk 0.44cvss 7.8epss 0.01

    OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument. To mitigate this issue, users should upgrade to…