在 projen 0.101.37 之前的版本中,生成的文件清单清理组件存在相对路径遍历漏洞。该漏洞可能允许依赖上下文的攻击者通过向版本控制的生成文件清单(该清单在合成项目时被使用)中植入特制条目,从而递归删除项目目录之外、且可被运行 projen 的环境写入的文件和目录。 要修复此问题,用户应升级至 0.101.37 版本。修正后的范围检查(containment check)将在下次运行 projen 时由 projen 运行时自动应用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89066 | 7.8 HIGH | OS command injection in the task synthesis component in projen |
| CVE-2026-18061 | 5.9 MEDIUM | Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper Remote |
| CVE-2026-89090 | 5.9 MEDIUM | Denial of service in the event stream header decoder in AWS SDK for Go v2 |
No comments yet