VYPR
Vendor

Localstack

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2021-32090CriMay 7, 2021
    risk 0.57cvss 9.8epss 0.02

    The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.

  • CVE-2023-48054HigNov 16, 2023
    risk 0.48cvss 7.4epss 0.00

    Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.

  • CVE-2021-32091MedMay 7, 2021
    risk 0.40cvss 6.1epss 0.01

    A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6.

  • CVE-2026-16763MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command…