AI and data stack advisories

Severe, 6 weeks2048Projects319

2048 severe, 6 weeks · 319 projects

AWSAWS-2026-131

Improper link resolution in asset bundling output handling in aws-cdk-lib

AWS

CVE-2026-107608 · Published Oct 8, 2026

Medium5.5
No fix yet
AWS advisory

Bulletin ID: 2026-131-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/08/2026 12:30 PM PDT Description: AWS CDK is an open source framework that allows customers to build cloud infrastructure using their favorite programming language (Python, Typescript, C#, Go). That infrastructure is then able to be deployed with AWS CDK command line commands to AWS CloudFormation. We identified CVE-2026-107608, which is an issue where Docker files could be configured to insert symlinked files into the output of the AWS CDK asset bundling process when it was invoked with a Docker file. When bundling an asset using AWS CDK with a docker file, prior to 2.267.0, it was possible for a docker file to insert a symlinked file or directory into the output of asset bundling without the symlink having been provided as input to the bundling process. Impacted versions: All aws-cdk-lib versions before 2.267.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

SeverityOct 9Severity: Unrated to Medium
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Severity from
NVD

More AWS advisories

All AWS