CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
Codecatalyst Blueprints ยท 2026-09-09
Actions
Technical Details
| Affected Versions | <= 0.3.155 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-85012 |
| Migration Required | Yes |
| Cost Impact | Neutral |
What This Means
For DevOps Teams
Update the @amazon-codecatalyst/blueprints.blueprint npm package to version 0.3.156 or later to address the OS command injection vulnerability (CVE-2026-85012) and ensure the security of your projects.
For Platform Teams
Deploy the updated @amazon-codecatalyst/blueprints.blueprint package (version 0.3.156 or later) across your platform to eliminate the risk of command injection attacks and maintain the security and integrity of your infrastructure.
For Executives
Implement the security patch for Amazon CodeCatalyst blueprints to mitigate the risk of command injection attacks and protect the organization's infrastructure and data.