CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection
Cybersecurity Classified by Officially
CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection
Bulletin ID: 2026-108-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/11/2026 09:00 AM PDT
projen is an open-source tool for defining and synthesizing software project configurations as code. AWS identified two issues in projen affecting the generated file manifest cleanup component and the task synthesis component.
We recommend upgrading to the latest version and ensuring any derivative code is patched to incorporate the new fixes.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-108-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 18, 2026 09:42
- Versions
- 1 recorded
- Identity
ef4cd83570acec55c1248107099ca3e5cc8be6bf