CVE-2026-7191 Details
Description
Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content Designer interface, which bypasses the intended expression sandbox through JavaScript prototype manipulation. This may grant direct access to backend resources (Lambda environment variables, OpenSearch indices, S3 objects, DynamoDB tables) that are not exposed through normal administrative interfaces. We recommend you upgrade to version 7.3.0 or above.
A vulnerability allowing arbitrary code execution has been identified in QnABot on AWS, specifically in versions through 7.2.4. This issue arises from improper use of the static-eval npm package, which may enable an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context. The vulnerability can be exploited by injecting a crafted conditional chaining expression through the Content Designer interface, manipulating the JavaScript prototype to bypass the intended expression sandbox. Successful exploitation could provide access to backend resources such as Lambda environment variables, OpenSearch indices, S3 objects, and DynamoDB tables, which are not typically available through standard administrative interfaces.
Users are advised to upgrade to QnABot on AWS version 7.3.0 or later, and to ensure that any forked or derivative code is also updated. Version 7.3.0 removes the static-eval dependency and replaces it with a custom expression evaluator. Instructions for downloading the latest version are available on the QnABot GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-020-aws/ | AMZN | |
| https://github.com/aws-solutions/qnabot-on-aws/releases/tag/v7.3.0 | AMZN |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | New CVE Received | AMZN |