Junglewise Threat Intelligence

AWS jsii-diff command injection via npm package argument

Severity: low · CVSS 3.1 · Published 2026-07-15

Vendors: AWS.

Executive brief

jsii-diff is an AWS tool used to compare versions of JavaScript/TypeScript libraries. The tool fails to properly validate package specifiers passed to its npm package loader, allowing an attacker to inject arbitrary shell commands. A malicious package name could lead to unauthorized code execution on a developer's machine during dependency analysis.

Technical details

This is an OS command injection vulnerability (CWE-78) in jsii-diff's npm package loading component. The vulnerable code accepts unsanitized package specifiers in the npm: source argument and passes them directly to shell commands without proper escaping or validation. The attack requires local code execution context and user interaction (running the tool with a crafted package specifier). An attacker can achieve arbitrary command execution with the privileges of the user running jsii-diff. The vulnerability was fixed in jsii-diff version 1.131.0 and later.

Affected products

  • AWS jsii-diff before 1.131.0

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: patched: Fixed in version 1.131.0
  • 2026-08-07: other: Advisory withdrawn as duplicate of GHSA-wcx4-wpfv-mc5c

References