projen Security Alert: Path Traversal and Command Injection Flaws
projen versions before 0.101.37 and 0.103.0 have two critical vulnerabilities. CVE-2026-89065 allows attackers to delete files outside your project directory through crafted manifest entries, while CVE-2026-89066 enables arbitrary command execution via shell metacharacters in config values. Update immediately—the fixes apply automatically on next runtime.
source: [aws/security-bulletin]