AWS CDK Command Injection Vulnerability Requires Immediate Update
AWS CDK (aws-cdk-lib) versions before 2.245.0 (2.246.0 on Windows) contain a nasty OS command injection flaw in the NodejsFunction bundling pipeline. If someone controls bundling properties like externalModules or esbuildArgs, they can execute arbitrary commands on your build machine—yikes! Update immediately if you're using affected versions and let untrusted code near your CDK configs.
source: [aws/security-bulletin]