CVE-2026-13760 - OS Command Injection in NodejsFunction Docker Bundling in aws-cdk-lib
Cdk Lib ยท 2026-07-01
Actions
Technical Details
| Affected Versions | < 2.260.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-13760 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update your aws-cdk-lib to version 2.260.0 and ensure that all dependencies come from trusted sources to address the OS command injection vulnerability (CVE-2026-13760).
For Platform Teams
Deploy the latest aws-cdk-lib version 2.260.0 to enhance the security of your infrastructure and avoid potential command injection attacks.
For Executives
Implement the upgrade to aws-cdk-lib version 2.260.0 to mitigate the risk of OS command injection and ensure the security of your cloud infrastructure.