Impact
The vulnerability is an OS command injection flaw located in the task synthesis component of projen before version 0.103.0. Due to improper neutralization of special elements, placeholders in project configuration values and repository file names are interpolated directly into generated shell commands. An attacker who can influence these project files can inject shell metacharacters, causing arbitrary commands to execute on developer workstations or continuous integration runners. The weakness aligns with CWE-78 and CWE-88, representing command injection and unsanitized input, respectively.
Affected Systems
As of the disclosed data, the affected product is Amazon Web Services projen. All installations using projen versions earlier than 0.103.0 are potentially compromised. This includes projects that rely on the task synthesis feature to generate .projen/tasks.json for build or deployment scripts.
Risk and Exploitability
The CVSS rating is 8.4, indicating high severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires the attacker to modify project configuration values or repository file names; once the project is synthesized, the malicious command becomes part of .projen/tasks.json and will execute when tasks are run. Because the resulting file may be committed to the repository, the attack can propagate through CI pipelines and potentially expose sensitive data or compromise build integrity.
OpenCVE Enrichment