CVE-2026-89065 and CVE-2026-89... Note

CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection

AWS has issued an important security bulletin regarding vulnerabilities in the projen open-source tool. Projen is used to define and synthesize software project configurations as code. Two specific issues have been identified, affecting different components of projen. CVE-2026-89065 is a relative path traversal vulnerability in the file manifest cleanup component. This could allow attackers to delete files and directories outside the project directory. This vulnerability is present in projen versions prior to 0.101.37. The fix for this issue is automatically applied by the projen runtime during its next execution. CVE-2026-89066 is an OS command injection vulnerability in the task synthesis component. Attackers could exploit this to execute arbitrary commands. This is possible through specially crafted project configuration values or file names. This vulnerability affects projen versions before 0.103.0. AWS advises users to refer to their article for the most current and comprehensive details.