Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later.
No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file. Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later. No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156. | |
| Title | OS command injection in the Amazon CodeCatalyst blueprints SDK | |
| First Time appeared |
Aws
Aws Amazon-codecatalyst Blueprints.blueprint |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:aws:_amazon-codecatalyst_blueprints.blueprint:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws Amazon-codecatalyst Blueprints.blueprint |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-03T17:30:24.814Z
Reserved: 2026-09-02T18:57:12.092Z
Link: CVE-2026-85012
Updated: 2026-09-03T17:30:20.915Z
Status : Received
Published: 2026-09-03T18:17:33.190
Modified: 2026-09-03T18:17:33.190
Link: CVE-2026-85012
No data.
OpenCVE Enrichment
Updated: 2026-09-03T20:30:10Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')