bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: AWS jsii

show all
Thursday, July 16, 2026

AWS jsii-diff Command Injection Vulnerability Requires Immediate Update

AWS jsii-diff, a CLI tool for comparing API differences between jsii assemblies, has a critical OS command injection flaw (CVE-2026-15895). Attackers can execute arbitrary shell commands through specially crafted command-line arguments. If you're running jsii-diff versions below 1.131.0, update immediately—this one's not optional, folks.

> source: aws.amazon.com