Sploitus

CVE-2026-11417

2 known exploits for CVE-2026-11417

OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This issue requires the threat actor to control the value of one or more of the affected bundling properties in the CDK application. To remediate this issue, users should upgrade to aws-cdk-lib 2.245.0 (2.246.0 on Windows) or later.

Affected products
Aws-Cdk-Lib
Fix
Available
CVSS 3.1
7.3 HIGH
EPSS
0.9% (58th percentile)
Weakness
CWE-78
NVD status
Awaiting Analysis
Published
2026-06-10
Attack patterns
CAPEC-88
CVE-2026-11417 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-11417

Proof-of-concept code and exploit modules indexed by Sploitus