bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, October 8, 2026

aws-cdk-lib Security Fix: Symlink Injection in Asset Bundling

aws-cdk-lib versions before 2.267.0 have a nasty vulnerability (CVE-2026-107608) where Docker files can sneak symlinked files into the asset bundling output without them being part of the original input. This could let attackers inject unwanted files into your cloud infrastructure deployments. If you're using AWS CDK with Docker files, update to 2.267.0 or later immediately—this one requires your attention.

source: [aws/security-bulletin]