OS Command Injection in Localstack Serverless-Localstack by Localstack
CVE-2026-16763
Key Information:
- Vendor
Localstack
- Status
- Vendor
- CVE Published:
- 23 July 2026
Badges
What is CVE-2026-16763?
A vulnerability exists in Localstack Serverless-Localstack versions up to 1.4.0, specifically within the Configuration Handler's index.js file. This security flaw allows an attacker to manipulate the 'custom.localstack.docker.compose_file' argument, potentially leading to OS command injection. Although the exploit requires local access to the system, it is publicly available, raising concerns about its misuse. Despite early notification to the project, no response has been recorded regarding this issue.
Affected Version(s)
serverless-localstack 1.0
serverless-localstack 1.1
serverless-localstack 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
