Impact
The ExcelLexBotS3TriggerFunction in wongcyrus ExcelLexBot allows manipulation that leads to improper privilege management, enabling an attacker to elevate privileges or gain unauthorized access. The CVE notes that the attack may be initiated remotely, implying exploitation through an S3 event trigger or direct API call. With elevated rights, an adversary could read, modify, or delete data, or disrupt services for accounts using the function.
Affected Systems
Versions of wongcyrus ExcelLexBot up to 0.0.3 are vulnerable. These releases are no longer supported by the maintainer, increasing the risk of unpatched exploits. The flaw resides in the Lambda function handler that processes S3 trigger events.
Risk and Exploitability
The CVSS score of 5.1 reflects moderate severity. EPSS data is not available, so known exploitation frequency remains unknown. The vulnerability is not listed in CISA KEV, indicating no confirmed widespread exploitation to date. However, because the flaw permits remote privilege escalation and the Lambda function may run with broad IAM permissions, organizations should treat this as a significant risk and address it promptly.
OpenCVE Enrichment