Impact
The vulnerability resides in the generated file manifest cleanup component of projen. It allows an attacker with context‑dependent access to the source repository to craft entries that reference paths outside the intended project directory. During project synthesis, projen interprets these entries and deletes files and directories outside the project that are writable by the runtime, leading to loss of data or infrastructure on the host machine. This is a classic relative path traversal flaw (CWE‑23).
Affected Systems
AWS Projen up to and including version 0.101.36 is vulnerable; any release prior to 0.101.37 contains the affected component. Users should upgrade to 0.101.37 or later to receive the containment fix.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity vulnerability. The EPSS score is not available, so exploitation probability cannot be quantified. The issue is not listed in CISA KEV. Attackers need the ability to influence the contents of the generated file manifest—typically through commit access or repository manipulation—and must run projen in an environment where it has filesystem write permissions. When these conditions are satisfied, the attacker can delete arbitrary files within the writable parent directories of the project, potentially causing serious data loss or service disruption.
OpenCVE Enrichment