Executive brief
The AWS Advanced NodeJS Wrapper is a database driver library that allows applications to connect to Amazon Aurora PostgreSQL databases. A low-privilege database user can exploit unsafe function creation to execute code with the permissions of other database users, potentially gaining superuser-level access. This allows an authenticated attacker to read sensitive data, modify database contents, or disrupt database availability.
Technical details
The vulnerability is a privilege escalation issue (CWE-470: unsafe reflection) in the AWS Advanced NodeJS Wrapper versions prior to 2.0.1. A low-privilege authenticated user can create a crafted PostgreSQL function that is executed with the permissions of other RDS users, potentially reaching rds_superuser role. The attack requires network access to the Aurora PostgreSQL instance and user interaction or specific conditions to trigger function execution. The vulnerability was patched in version 2.0.1 by fully qualifying PostgreSQL SQL queries, preventing unintended schema resolution that could allow privilege escalation.
Affected products
- AWS Advanced NodeJS Wrapper < 2.0.1
Timeline
- 2025-11-10: disclosed
- 2025-11-13: patched: Version 2.0.1 released