CVE-2026-107608
EUVD-2026-9525208.10.2026, 20:17
Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset. To remediate this issue, users should upgrade to version 2.267.0 or later.
Awaiting analysis
This vulnerability is currently awaiting analysis.