CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection

AWS ยท 2026-09-11

Actions

Rate this issue

Technical Details

Affected Versions before 0.101.37, before 0.103.0
Regions all
CVE IDs CVE-2026-89065, CVE-2026-89066
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update projen to version 0.101.37 or later to address CVE-2026-89065, and to version 0.103.0 or later to address CVE-2026-89066, ensuring to re-synthesize your project to regenerate.projen/tasks.json with the corrected task definitions to mitigate security risks and maintain project integrity.

For Platform Teams

Integrate the latest projen updates into your project configurations to address critical security vulnerabilities, ensuring that your IaC practices remain secure and compliant with the latest standards.

For Executives

Implement immediate upgrades to projen to address critical security vulnerabilities (CVE-2026-89065 and CVE-2026-89066) and ensure the security and integrity of project configurations, thereby mitigating potential risks and maintaining operational stability.

Source

View original AWS announcement โ†’

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.