AWS Toolkit for VS Code 4.10.0 之前的版本中,CodeCatalyst 连接处理器存在不安全的文件权限漏洞,本地用户可通过读取全局可读的令牌缓存文件,获取 CodeCatalyst 的 bearer 令牌。 为缓解此问题,建议用户升级至 4.10.0 或更高版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| aws | aws-toolkit-vscode | < 4.10.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aws | aws-toolkit-vscode | 0 ~ 4.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107322 | 7.8 HIGH | OS command injection in Amazon Agent Plugins for AWS databases-on-aws |
| CVE-2026-107608 | 5.5 MEDIUM | Improper link resolution in asset bundling output handling in aws-cdk-lib |
No comments yet