bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

AWS CDK Command Injection Vulnerability Requires Immediate Update

AWS CDK (aws-cdk-lib) versions before 2.245.0 (2.246.0 on Windows) contain a nasty OS command injection flaw in the NodejsFunction bundling pipeline. If someone controls bundling properties like externalModules or esbuildArgs, they can execute arbitrary commands on your build machine—yikes! Update immediately if you're using affected versions and let untrusted code near your CDK configs.

source: [aws/security-bulletin]