Description
Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled generated file manifest that is consumed during project synthesis.



To remediate this issue, users should upgrade to version 0.101.37. The corrected containment check is automatically applied by the projen runtime next time you run it.
Published: 2026-09-11
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: File Deletion via Path Traversal
Action: Upgrade Now
AI Analysis

Impact

The vulnerability resides in the generated file manifest cleanup component of projen. It allows an attacker with context‑dependent access to the source repository to craft entries that reference paths outside the intended project directory. During project synthesis, projen interprets these entries and deletes files and directories outside the project that are writable by the runtime, leading to loss of data or infrastructure on the host machine. This is a classic relative path traversal flaw (CWE‑23).

Affected Systems

AWS Projen up to and including version 0.101.36 is vulnerable; any release prior to 0.101.37 contains the affected component. Users should upgrade to 0.101.37 or later to receive the containment fix.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium severity vulnerability. The EPSS score is not available, so exploitation probability cannot be quantified. The issue is not listed in CISA KEV. Attackers need the ability to influence the contents of the generated file manifest—typically through commit access or repository manipulation—and must run projen in an environment where it has filesystem write permissions. When these conditions are satisfied, the attacker can delete arbitrary files within the writable parent directories of the project, potentially causing serious data loss or service disruption.

Generated by OpenCVE AI on September 11, 2026 at 17:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to projen version 0.101.37 or later to activate the containment check.
  • Run projen with the working directory mapped as read‑only or in a container that limits write access to the filesystem, to prevent accidental deletions if an upgrade cannot be performed immediately.
  • Temporarily review the version‑controlled generated file manifest and remove or correct any entries that reference parent or cross‑directory paths before running projen.

Generated by OpenCVE AI on September 11, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled generated file manifest that is consumed during project synthesis. To remediate this issue, users should upgrade to version 0.101.37. The corrected containment check is automatically applied by the projen runtime next time you run it.
Title Relative path traversal in the generated file manifest cleanup component in projen
First Time appeared Aws
Aws projen
Weaknesses CWE-23
CPEs cpe:2.3:a:aws:projen:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws projen
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-11T16:22:01.470Z

Reserved: 2026-09-10T18:43:41.912Z

Link: CVE-2026-89065

cve-icon Vulnrichment

Updated: 2026-09-11T16:21:47.680Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T16:17:49.253

Modified: 2026-09-11T18:24:59.400

Link: CVE-2026-89065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T21:45:03Z

Weaknesses
  • CWE-23

    Relative Path Traversal