Insecure File Permissions in AWS Toolkit for VS Code Affecting CodeCatalyst
CVE-2026-107332

6.8MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107332?

The AWS Toolkit for VS Code exhibits insecure file permissions within its CodeCatalyst connection handler, which prior to version 4.10.0 allowed local users to access sensitive bearer tokens. This vulnerability arises from the existence of world-readable token cache files, enabling unauthorized reading of these tokens. To protect your development environment, it is crucial to upgrade to version 4.10.0 or later, thereby mitigating the risks posed by this security flaw and securing your CodeCatalyst credentials.

Affected Version(s)

aws-toolkit-vscode 0 < 4.10.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.