SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-15895

HIGH · CVSS 7.8 EPSS 0.63% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The npm package loading component in AWS jsii-diff prior to version 1.131.0 is vulnerable to OS command injection, allowing attackers to execute arbitrary commands through specially crafted package specifiers. This high-severity vulnerability poses a significant risk to users who rely on this component for package management. Organizations utilizing jsii-diff should prioritize upgrading to version 1.131.0 or later to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15895
Severity
HIGH
CVSS
7.8
EPSS
0.63%

Original NVD Description

OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument. To mitigate this issue, users should upgrade to jsii-diff v1.131.0 or later.