Description
Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions.



To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Command Execution
Action: Immediate Upgrade
AI Analysis

Impact

The vulnerability is an OS command injection flaw located in the task synthesis component of projen before version 0.103.0. Due to improper neutralization of special elements, placeholders in project configuration values and repository file names are interpolated directly into generated shell commands. An attacker who can influence these project files can inject shell metacharacters, causing arbitrary commands to execute on developer workstations or continuous integration runners. The weakness aligns with CWE-78 and CWE-88, representing command injection and unsanitized input, respectively.

Affected Systems

As of the disclosed data, the affected product is Amazon Web Services projen. All installations using projen versions earlier than 0.103.0 are potentially compromised. This includes projects that rely on the task synthesis feature to generate .projen/tasks.json for build or deployment scripts.

Risk and Exploitability

The CVSS rating is 8.4, indicating high severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires the attacker to modify project configuration values or repository file names; once the project is synthesized, the malicious command becomes part of .projen/tasks.json and will execute when tasks are run. Because the resulting file may be committed to the repository, the attack can propagate through CI pipelines and potentially expose sensitive data or compromise build integrity.

Generated by OpenCVE AI on September 11, 2026 at 17:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade projen to version 0.103.0 or later
  • After upgrading, re‑synthesize the project to regenerate a cleaned .projen/tasks.json
  • Remove any previously committed .projen/tasks.json from the repository and redeploy CI runners

Generated by OpenCVE AI on September 11, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:30:00 +0000


Fri, 11 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions. To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository.
Title OS command injection in the task synthesis component in projen
First Time appeared Aws
Aws projen
Weaknesses CWE-78
CWE-88
CPEs cpe:2.3:a:aws:projen:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws projen
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-11T16:21:02.834Z

Reserved: 2026-09-10T18:44:43.656Z

Link: CVE-2026-89066

cve-icon Vulnrichment

Updated: 2026-09-11T16:20:59.373Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T16:17:49.400

Modified: 2026-09-11T18:24:59.400

Link: CVE-2026-89066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:55:44Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')