Command Injection Vulnerability in AWS Codecatalyst-Blueprints Framework
CVE-2026-85012

8.5HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
3 September 2026

What is CVE-2026-85012?

The AWS Codecatalyst-Blueprints framework experienced a vulnerability due to improper handling of special elements used in OS commands, allowing users with repository access to execute arbitrary commands. This could occur through the manipulation of the owner field in a crafted .ownership-file, facilitating shell metacharacter command injection. Version 0.3.156 addresses this issue by eliminating shell interpretation in the owner field and enforcing command validation against an allowlist. Users are encouraged to update to this version or later to mitigate potential exploitation risks.

Affected Version(s)

@amazon-codecatalyst/blueprints.blueprint 0 < 0.3.156

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.