aws-cdk-lib Security Fix: Symlink Injection in Asset Bundling
aws-cdk-lib versions before 2.267.0 have a nasty vulnerability (CVE-2026-107608) where Docker files can sneak symlinked files into the asset bundling output without them being part of the original input. This could let attackers inject unwanted files into your cloud infrastructure deployments. If you're using AWS CDK with Docker files, update to 2.267.0 or later immediately—this one requires your attention.
source: [aws/security-bulletin]