VYPR

AWS CDK CLI

by AWS

Source repositories

CVEs (6)

  • CVE-2025-23206HigJan 17, 2025
    risk 0.46cvss 8.1epss 0.00

    The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom…

  • CVE-2023-35165MedJun 23, 2023
    risk 0.43cvss 6.6epss 0.01

    AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. In the packages `aws-cdk-lib` 2.0.0 until 2.80.0 and `@aws-cdk/aws-eks` 1.57.0 until 1.202.0, `eks.Cluster`…

  • CVE-2026-13760HigJul 1, 2026
    risk 0.41cvss 7.3epss 0.01

    OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platforms might allow a actor who controls dependency version strings in a project's package.json file to execute arbitrary commands on the host running the CDK…

  • CVE-2026-11417HigJun 10, 2026
    risk 0.40cvss 7.3epss 0.01

    OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary…

  • CVE-2024-45037MedAug 27, 2024
    risk 0.35cvss 6.4epss 0.00

    The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own applications which are converted to AWS CloudFormation templates during deployment to a customer’s AWS account. CDK contains…

  • CVE-2026-13769MedJul 1, 2026
    risk 0.29cvss 5.5epss 0.00

    Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the same host to read credentials written by…