Impact
The vulnerability arises from an improper link resolution before file access in the asset bundling output handling of AWS aws-cdk-lib. A context‑dependent actor can exploit this flaw to cause files that reside on the build host to be published as part of the deployed asset. This can lead to unintended disclosure of internal files and, if attacker‑controlled payloads are included, may provide a path to execute malicious code on the deployment target.
Affected Systems
Affecting the AWS Software Development Kit (AWS CDK) library, specifically any deployment that utilizes aws-cdk-lib prior to version 2.267.0. Users running older builds of the library without the patch are exposed.
Risk and Exploitability
The CVSS score of 6.8 categorizes the issue as Moderate severity. No EPSS value is available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an actor with access to the build environment and enough context to influence the asset bundling process. The attack vector is inferred as a build‑time supply‑chain manipulation rather than remote network access.
OpenCVE Enrichment