AWS jsii-diff Command Injection Vulnerability Requires Immediate Update
AWS jsii-diff, a CLI tool for comparing API differences between jsii assemblies, has a critical OS command injection flaw (CVE-2026-15895). Attackers can execute arbitrary shell commands through specially crafted command-line arguments. If you're running jsii-diff versions below 1.131.0, update immediately—this one's not optional, folks.