Back to database
Soon68Medium6.8VulnerabilityCVE-2026-107608No patch link observed

CVE-2026-107608 — Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent…

Published Oct 8, 2026, 08:17 PM UTCIngested 1h agoSource NVD(cve-db)CVE-2026-107608

Description

Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset. To remediate this issue, users should upgrade to version 2.267.0 or later.

CVSS v4.0 base metrics

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.8

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Local

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

None

Privileges Required

UI

Passive

User Interaction

VC

High

Confidentiality (Vulnerable System)

VI

None

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

None

Confidentiality (Subsequent System)

SI

None

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)