Impact
The vulnerability resides in localstack serverless-localstack releases up to 1.4.0 and is triggered through manipulation of the custom.localstack.docker.compose_file argument in the Configuration Handler’s src/index.js. By supplying a crafted value, an attacker can inject arbitrary operating‑system commands that are executed within the host environment, exploiting the weaknesses listed as CWE‑77 and CWE‑78. The security impact is the ability to run arbitrary code locally, potentially compromising the host system’s confidentiality, integrity, or availability.
Affected Systems
All installations of the localstack serverless-localstack component up to version 1.4.0 are affected. The issue is confined to this specific product; other Localstack modules are not known to be impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access, but an exploit has already been made publicly available, meaning an attacker with local presence could achieve command execution easily once the vulnerability is known. The absence of a published fix underscores the need for immediate remediation.
OpenCVE Enrichment