CVE-2026-15895 Details
Description
OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument. To mitigate this issue, users should upgrade to jsii-diff v1.131.0 or later.
A command injection vulnerability has been identified in the AWS jsii-diff tool, which is used to compare API differences between two jsii assemblies. This issue affects versions prior to 1.131.0. The vulnerability allows context-dependent attackers to execute arbitrary commands by crafting specific package specifiers that are passed to the npm: source argument. The problem arises from the way jsii-diff handles command line arguments, which can be manipulated to inject and execute shell commands.
Users are advised to upgrade to jsii-diff version 1.131.0 or later. If an immediate upgrade is not possible, ensure that only trusted individuals can control the arguments sent to the jsii-diff tool.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-057-aws/ | AMZN | |
| https://github.com/aws/jsii/releases/tag/v1.131.0 | AMZN |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | AMZN |