Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK

Amazon Web Services Version 1 original

Imported from official source

Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT Description: Amazon CodeCatalyst blueprints are reusable project templates that generate a software project. The @amazon-codecatalyst/blueprints.blueprint npm package is the open source framework that blueprint authors build on, published from github.com/aws/codecatalyst-blueprints. We identified CVE-2026-85012 in the blueprint resynthesis framework. During resynthesis, the framework reads the .ownership-file from the existing project to determine which files a bluepri...

This version

Version
1 of 2
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
0db3e4436aa5f92202f274588b684f70
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.