CVE-2026-15895: OS command injection in jsii-diff in AWS jsii
Cybersecurity Classified by Officially
CVE-2026-15895: OS command injection in jsii-diff in AWS jsii
Bulletin ID: 2026-057-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 07/15/2026 12:00 PM PDT
Last Updated Date: 07/16/2026 10:30 AM PDT
jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. We identified CVE-2026-15895, an issue where specially formatted command line arguments can be used to execute shell commands via this tool.
This issue has been addressed in jsii-diff version 1.131.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
If you are unable to update, make sure only trusted actors can control the arguments passed to jsii-diff.
We would like to thank Junming Wu for collaborating on this issue through the coordinated vulnerability disclosure process.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-057-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 29, 2026 16:00
- Versions
- 1 recorded
- Identity
3b018c56f5ef0855d9efae4c414e32282c9c9d0b