Issue with projen - Path traversal and OS command injection
UnratedCVE-2026-89065 · Published Sep 11, 2026
Bulletin ID: 2026-108-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:00 AM PDT Description: projen is an open-source tool for defining and synthesizing software project configurations as code. AWS identified two issues in projen affecting the generated file manifest cleanup component and the task synthesis component. - CVE-2026-89065 — Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory, via crafted entries in the version-controlled generated file manifest (.projen/files.json) that is consumed during project synthesis. The corrected containment check is automatically applied by the projen runtime the next time it is run. - CVE-2026-89066 — Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are i...
Affected versions
Details and references
Bulletin ID: 2026-108-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:00 AM PDT Description: projen is an open-source tool for defining and synthesizing software project configurations as code. AWS identified two issues in projen affecting the generated file manifest cleanup component and the task synthesis component. - CVE-2026-89065 — Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory, via crafted entries in the version-controlled generated file manifest (.projen/files.json) that is consumed during project synthesis. The corrected containment check is automatically applied by the projen runtime the next time it is run. - CVE-2026-89066 — Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions in .projen/tasks.json. Impacted versions: - All projen versions before 0.101.37 (CVE-2026-89065) - All projen versions before 0.103.0 (CVE-2026-89066) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
- Severity from
- no source yet
- Also known as
- CVE-2026-89066
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration | Unrated | No fix yet |
| Sep 11 | Denial of service in the event stream header decoder in AWS SDK for Go v2 | Unrated | No fix yet |
| Sep 11 | XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin | Unrated | No fix yet |
| Sep 10 | Server-side request forgery in the Session Manager port forwarding functionality in AWS... | Unrated | No fix yet |
| Sep 10 | Integer overflow in tensor buffer validation in Deep Java Library | Unrated | No fix yet |
| Sep 10 | Missing S3 bucket ownership verification in the AWS Security Agent plugin for... | Unrated | No fix yet |