CVE-2026-107332

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files. To mitigate this issue, users should upgrade to version 4.10.0 or later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276CWE-459

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-08: 1Mentions · 2026-10-09: 110-0810-09
Referenced assets1 URL
By indicator
Full discourse2 posts
  • multilayer@multilayer

    10/8〜9(日本時間)に、クラウド関連のセキュリティ情報が続けて公開された。いずれも悪用は確認されていない。 Azure SRE Agent の CVE-2026-69435 は、権限昇格につながるSSRFの脆弱性で、深刻度はCritical(CVSS 9.6)。Microsoftがすでにサービス側で対策を済ませていて、利用者の対応は不要。 AWS Toolkit for VS Code の CVE-2026-107332 は、CodeCatalystのDev Environmentに接続したとき、ベアラートークンを誰でも読める権限のファイルに保存し、セッション終了後も消していなかった問題。同じマシンの別ユーザーやプロセスがトークンを読める。4.10.0以降で修正済み。 aws-cdk-lib の CVE-2026-107608 は、Dockerfileを使ったアセットのバンドル時に、入力にないシンボリックリンクを出力に紛れ込ませられる問題。2.267.0以降で修正済み。 Azureは何もしなくてよいが、AWSの2件は手元のツールのバージョンを確認して更新しておきたい。共有の開発マシンでToolkitを使っている場合や、Dockerでのバンドルに外部のイメージを使っている場合は特に。 #セキュリティ #AWS #Azure #脆弱性 https://aws.amazon.com/security/security-bulletins/

    0000091
    804 followersView on X
  • Saint Intelligence@Saint_Intel

    Nueva vulnerabilidad CVE-2026-107332 (severidad: Alta) del fabricante AWS.

    0000024
    295 followersView on X

Explore more