To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 11 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions. To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository. | |
| Title | OS command injection in the task synthesis component in projen | |
| First Time appeared |
Aws
Aws projen |
|
| Weaknesses | CWE-78 CWE-88 |
|
| CPEs | cpe:2.3:a:aws:projen:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws projen |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-11T16:21:02.834Z
Reserved: 2026-09-10T18:44:43.656Z
Link: CVE-2026-89066
No data.
Status : Received
Published: 2026-09-11T16:17:49.400
Modified: 2026-09-11T17:19:31.453
Link: CVE-2026-89066
No data.
OpenCVE Enrichment
No data.