CVE-2026-13760Disclosure

LOWCVSS 7.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platforms might allow a actor who controls dependency version strings in a project's package.json file to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters in the OsCommand helper. This issue requires the actor to control the content of a package.json dependency version string that is processed during Docker-based bundling with nodeModules specified. To remediate this issue, users should upgrade to v2.260.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 107-02
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Eyal Estrin ☁️@eyalestrin
    Disclosure

    CVE-2026-13760 - OS Command Injection in NodejsFunction Docker Bundling in aws-cdk-lib http://dlvr.it/TTKY0l #patchmanagement

    Post summary

    The tweet announces a newly discovered OS Command Injection vulnerability in aws‑cdk‑lib’s Docker bundling, references additional documentation, but does not provide exploit code or detailed patch instructions.

    0000044
    2.0K followersView on X

Explore more