Symlink Vulnerability in AWS Serverless Application Model CLI
CVE-2025-3048
Key Information:
- Vendor
Aws
- Vendor
- CVE Published:
- 31 March 2025
What is CVE-2025-3048?
A vulnerability exists in the AWS Serverless Application Model Command Line Interface (SAM CLI) related to symlinks. When building projects using SAM CLI that include symlinks, the contents are inadvertently copied to the local workspace's cache as regular files or directories. This unintentionally grants access to users who would typically not have permissions to those symlinked content outside the Docker container. To mitigate this risk, users must upgrade to version 1.134.0 and ensure that any specific customizations or forked codebases also implement the necessary patches. After upgrading, rebuilding applications with the command 'sam build --use-container' is crucial for rectifying the access control issues introduced by this vulnerability.
Affected Version(s)
AWS Serverless Application Model Command Line Interface 1.9.0 < 1.134.0