aws-cdk-lib Command Injection Vulnerability Requires Immediate Update
AWS CDK (aws-cdk-lib) versions before 2.260.0 have a nasty OS command injection flaw in NodejsFunction Docker bundling. If someone controls your package.json dependency versions, they can execute arbitrary commands on your build machine through shell metacharacters. Action required: upgrade to 2.260.0+ if you use Docker-based bundling with nodeModules.