Amazon CodeCatalyst Blueprints SDK: OS Command Injection Vulnerability
Amazon CodeCatalyst blueprints SDK versions before 0.3.156 contain a command injection vulnerability (CVE-2026-85012) in the resynthesis framework. An attacker with repository commit access could inject shell metacharacters into the .ownership-file to execute arbitrary commands. Good news: no user action needed—AWS applies server-side validation that blocks this attack on the service side, even for older blueprint versions.
source: [aws/security-bulletin]