Improper Link Resolution in AWS Asset Bundling Library
CVE-2026-107608

6.8MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107608?

The AWS aws-cdk-lib library prior to version 2.267.0 is susceptible to a vulnerability that allows improper link resolution prior to file access. This could enable an attacker to exploit the output handling process, potentially leading to the inclusion of files from the build host as deployed assets. To mitigate this risk, it is strongly advised to upgrade to version 2.267.0 or later.

Affected Version(s)

aws-cdk-lib 0 < 2.267.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.