Aws Projen
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Aws Projen.
By the Year
In 2026 there have been 2 vulnerabilities in Aws Projen with an average score of 7.5 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 7.45 |
It may take a day or so for new Projen vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Aws Projen Security Vulnerabilities
projen <0.103.0 Task Injection via Shell Metacharacters
CVE-2026-89066
7.8 - High
- September 11, 2026
Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions. To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository.
Shell injection
Relative path traversal in projen <0.101.37: recursive file deletion
CVE-2026-89065
7.1 - High
- September 11, 2026
Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled generated file manifest that is consumed during project synthesis. To remediate this issue, users should upgrade to version 0.101.37. The corrected containment check is automatically applied by the projen runtime next time you run it.
Relative Path Traversal
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Aws Projen or by Aws? Click the Watch button to subscribe.