Command Injection Vulnerability in AWS Codecatalyst-Blueprints Framework
CVE-2026-85012
8.5HIGH
Key Information:
- Vendor
Aws
- Vendor
- CVE Published:
- 3 September 2026
What is CVE-2026-85012?
The AWS Codecatalyst-Blueprints framework experienced a vulnerability due to improper handling of special elements used in OS commands, allowing users with repository access to execute arbitrary commands. This could occur through the manipulation of the owner field in a crafted .ownership-file, facilitating shell metacharacter command injection. Version 0.3.156 addresses this issue by eliminating shell interpretation in the owner field and enforcing command validation against an allowlist. Users are encouraged to update to this version or later to mitigate potential exploitation risks.
Affected Version(s)
@amazon-codecatalyst/blueprints.blueprint 0 < 0.3.156
