CVE-2026-107608
Awaiting Analysis Awaiting Analysis - Queue

Improper Link Resolution in AWS CDK Before 2.267.0

Vulnerability report for CVE-2026-107608, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: AMZN

Description

Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset. To remediate this issue, users should upgrade to version 2.267.0 or later.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
AWS aws-cdk-lib 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper link resolution before file access in the asset bundling output handling of AWS aws-cdk-lib versions before 2.267.0. It allows a context-dependent actor to cause files from the build host to be published as the deployed asset, potentially leading to unintended data exposure or manipulation.

Detection Guidance

Detecting this vulnerability requires checking the version of aws-cdk-lib in use. Run 'npm list aws-cdk-lib' or 'yarn list aws-cdk-lib' to verify if the installed version is below 2.267.0. Inspect Docker bundling containers for untrusted code execution or symlinked files in output directories.

Impact Analysis

An attacker could exploit this to insert symlinked files or directories into the bundling output without providing the symlink as input. This may result in sensitive files from the build host being published as deployed assets, leading to data exposure or unauthorized modifications.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, which may violate compliance requirements such as GDPR or HIPAA. Unintended publication of sensitive files could result in data breaches, triggering regulatory penalties and legal consequences.

Mitigation Strategies

Upgrade aws-cdk-lib to version 2.267.0 or later immediately. If upgrading is not possible, audit Docker bundling containers and their dependencies to prevent untrusted code execution in the bundling environment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107608. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart