Executive brief
jsii-diff is an AWS tool used to compare versions of JavaScript/TypeScript libraries. The tool fails to properly validate package specifiers passed to its npm package loader, allowing an attacker to inject arbitrary shell commands. A malicious package name could lead to unauthorized code execution on a developer's machine during dependency analysis.
Technical details
This is an OS command injection vulnerability (CWE-78) in jsii-diff's npm package loading component. The vulnerable code accepts unsanitized package specifiers in the npm: source argument and passes them directly to shell commands without proper escaping or validation. The attack requires local code execution context and user interaction (running the tool with a crafted package specifier). An attacker can achieve arbitrary command execution with the privileges of the user running jsii-diff. The vulnerability was fixed in jsii-diff version 1.131.0 and later.
Affected products
- AWS jsii-diff before 1.131.0
Timeline
- 2026-07-15: disclosed
- 2026-07-15: patched: Fixed in version 1.131.0
- 2026-08-07: other: Advisory withdrawn as duplicate of GHSA-wcx4-wpfv-mc5c