Junglewise Threat Intelligence

CVE-2026-89066: projen OS command injection in task synthesis

CVE-2026-89066 · Severity: high · CVSS 7.8 · Published 2026-09-11

Executive brief

projen is an open-source tool for defining software project configurations as code. A flaw in how it generates task definitions allows attackers to inject shell commands by embedding metacharacters in project configuration values or file names, potentially enabling arbitrary code execution on developer workstations or CI/CD runners.

Technical details

This is an OS command injection vulnerability (CWE-78) in projen's task synthesis component. The root cause is improper neutralization of shell metacharacters when interpolating project configuration values (such as LambdaFunctionOptions.entrypoint, JestOptions.extraCliOptions, PytestOptions.testMatch, ReleaseOptions.artifactsDirectory) and repository file names into generated task definitions in .projen/tasks.json. An attacker with control over project configuration files or repository structure can embed shell metacharacters to execute arbitrary commands when tasks are executed. This affects developers and CI/CD runners that synthesize and execute these tasks. The vulnerability is fixed in projen 0.103.0, but users must both upgrade and re-synthesize their projects to regenerate the task definition file, since the corrupted definitions are typically committed to version control.

Affected products

  • projen projen before 0.103.0

Timeline

  • 2026-09-11: disclosed
  • 2026-08-21: patched: v0.103.0 released

References