Disclosure summary
Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files. To mitigate this issue, users should upgrade to version 4.10.0 or later.
Source-reported weakness categories
CWE-276, CWE-459
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107332
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Latest Bulletins · RSS-0a930818b7ded66af4a958bb13624737d8d
Open original source · Updated Oct 08, 2026
CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code
CVE mention in publisher metadata; check the original affected versions.
Original records & references
PUBLISHED 2026-10-08T14:17:19-04:00
MODIFIED 2026-10-09T13:16:45-04:00
INGESTED 2026-10-10T20:55:03-04:00