Executive brief
projen is an open-source tool for defining software project configurations as code. A flaw in how it generates task definitions allows attackers to inject shell commands by embedding metacharacters in project configuration values or file names, potentially enabling arbitrary code execution on developer workstations or CI/CD runners.
Technical details
This is an OS command injection vulnerability (CWE-78) in projen's task synthesis component. The root cause is improper neutralization of shell metacharacters when interpolating project configuration values (such as LambdaFunctionOptions.entrypoint, JestOptions.extraCliOptions, PytestOptions.testMatch, ReleaseOptions.artifactsDirectory) and repository file names into generated task definitions in .projen/tasks.json. An attacker with control over project configuration files or repository structure can embed shell metacharacters to execute arbitrary commands when tasks are executed. This affects developers and CI/CD runners that synthesize and execute these tasks. The vulnerability is fixed in projen 0.103.0, but users must both upgrade and re-synthesize their projects to regenerate the task definition file, since the corrupted definitions are typically committed to version control.
Affected products
- projen projen before 0.103.0
Timeline
- 2026-09-11: disclosed
- 2026-08-21: patched: v0.103.0 released