Symlink Vulnerability in AWS Serverless Application Model CLI
CVE-2025-3048

6.9MEDIUM

What is CVE-2025-3048?

A vulnerability exists in the AWS Serverless Application Model Command Line Interface (SAM CLI) related to symlinks. When building projects using SAM CLI that include symlinks, the contents are inadvertently copied to the local workspace's cache as regular files or directories. This unintentionally grants access to users who would typically not have permissions to those symlinked content outside the Docker container. To mitigate this risk, users must upgrade to version 1.134.0 and ensure that any specific customizations or forked codebases also implement the necessary patches. After upgrading, rebuilding applications with the command 'sam build --use-container' is crucial for rectifying the access control issues introduced by this vulnerability.

Affected Version(s)

AWS Serverless Application Model Command Line Interface 1.9.0 < 1.134.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.