FR
live
High CVSS 7.3

CVE-2026-13760

NVD analysis in progress

OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platforms might allow a actor who controls dependency version strings in a project's package.json file to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters in the OsCommand helper. This issue requires the actor to control the content of a package.json dependency version string that is processed during Docker-based bundling with nodeModules specified. To remediate this issue, users should upgrade to v2.260.0.

What this means

Exposure
Exploitable with local access to the machine and with an ordinary user account — but only if a user opens booby-trapped content.
Impact
An attacker can read sensitive data, modify or destroy data and take the service offline.
Weakness
Unfiltered input reaches the system shell, letting the attacker run their own commands on the server.
Likelihood
Its EPSS score stays low: nothing points to imminent exploitation, which is no reason to leave it unpatched.

What to doFold into the next patch cycle.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
1 July 2026
CVSS
7.3 (v3.1) CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS
0.63% probability of exploitation within 30 days · above 46% of all CVEs
Weakness
CWE-78
Sources
nvd
References

Type at least two characters.

navigate open esc dismiss