CVE-2026-107608 | AWS aws-cdk-lib up to 2.266.x Asset Bundling Output path traversal

SecurityVulns

A vulnerability described as problematic has been identified in AWS aws-cdk-lib up to 2.266.x. Impacted is an unknown function of the component Asset Bundling Output Handler. Such manipulation leads to path traversal.

This vulnerability is traded as CVE-2026-107608. An attack has to be approached locally. There is no exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More