
Cybersecurity
AWS patches command execution and path traversal flaws in projen
31 minutes ago
AWS disclosed two serious vulnerabilities in the projen project generator on Friday September 11 that could allow crafted repository data to delete files outside a project directory or execute arbitrary commands on developer workstations and continuous integration runners. The flaws affect versions up to 0.101.37 and 0.103.0, requiring teams to upgrade and then re-synthesize all projects so that generated task definitions no longer contain the vulnerable code. The disclosure underscores persistent risks in widely adopted developer tooling that touches every stage of the software supply chain.










