Impact
OS command injection in AWS jsii‑diff’s npm package loader allows attackers to supply a crafted npm:source argument, causing arbitrary command execution via the operating system, which is a CWE‑78 vulnerability and enables remote code execution on the host running jsii‑diff, jeopardizing confidentiality, integrity, and availability of the build environment.
Affected Systems
All versions of AWS jsii‑diff earlier than 1.131.0 are vulnerable. Users who run these releases in CI/CD pipelines, build scripts, or other automated contexts are at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, yet the EPSS score of < 1% suggests exploitation is unlikely under normal circumstances. Because the vulnerability requires a crafted npm source argument, attackers would need to influence the build configuration or supply untrusted package specifiers. If exploited, the attacker would gain unrestricted command execution on the host, potentially compromising the entire build infrastructure. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment