Disclosure summary
Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset. To remediate this issue, users should upgrade to version 2.267.0 or later.
Source-reported weakness categories
CWE-59
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107608
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Latest Bulletins · RSS-ad5f44432b340c99008a5ecc7f46d5a2479
Open original source · Updated Oct 08, 2026
CVE-2026-107608: Improper link resolution in asset bundling output handling in aws-cdk-lib
CVE mention in publisher metadata; check the original affected versions.
Original records & references
PUBLISHED 2026-10-08T16:17:34-04:00
MODIFIED 2026-10-08T17:33:42-04:00
INGESTED 2026-10-10T20:55:03-04:00