CVE-2026-107608: Aws Aws-Cdk-Lib
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset. To remediate this issue, users should upgrade to version 2.267.0 or later.
Affected products
- Aws Aws-Cdk-Lib: before 2.267.0 (fixed in 2.267.0)
Published 2026-10-08. Last modified 2026-10-08.