CVE-2026-107608 | AWS aws-cdk-lib up to 2.266.x Asset Bundling Output path traversal
A vulnerability described as problematic has been identified in AWS aws-cdk-lib up to 2.266.x. Impacted is an unknown function of the component Asset Bundling Output Handler. Such manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-107608. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More