Aws Amazon Codecatalyst Blueprints Blueprint
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Aws Amazon Codecatalyst Blueprints Blueprint.
By the Year
In 2026 there have been 1 vulnerability in Aws Amazon Codecatalyst Blueprints Blueprint with an average score of 8.0 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 8.00 |
It may take a day or so for new Amazon Codecatalyst Blueprints Blueprint vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Aws Amazon Codecatalyst Blueprints Blueprint Security Vulnerabilities
AWS CodeCatalyst Blueprint Resynthesis OS Command Injection (CWE-78) <0.3.156
CVE-2026-85012
8 - High
- September 03, 2026
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later. No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.
Shell injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Aws Amazon Codecatalyst Blueprints Blueprint or by Aws? Click the Watch button to subscribe.