CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection
Two vulnerabilities were identified in the open-source tool projen affecting versions before 0.101.37 and 0.103.0. CVE-2026-89065 is a relative path traversal issue in the generated file manifest cleanup component that may allow attackers to delete files outside the project directory. CVE-2026-89066 is an OS command injection vulnerability in the task synthesis component that could enable arbitrary command execution on developer workstations or CI runners via shell metacharacters in project configuration or repository file names. Fixes are available in projen versions 0.101.37 and 0.103.0 respectively. Users must upgrade and, for CVE-2026-89066, re-synthesize their projects to regenerate safe task definitions.
AI Analysis
Technical Summary
AWS identified two security issues in projen, an open-source project configuration tool. CVE-2026-89065 involves a relative path traversal vulnerability in the file manifest cleanup component in versions before 0.101.37, which could allow context-dependent attackers to recursively delete files and directories outside the project directory via crafted entries in the version-controlled generated file manifest (.projen/files.json). The fix is automatically applied by the projen runtime from version 0.101.37 onward. CVE-2026-89066 is an OS command injection vulnerability in the task synthesis component in versions before 0.103.0. This flaw allows context-dependent attackers to execute arbitrary OS commands on developer workstations or CI runners by injecting shell metacharacters into project configuration values or repository file names that are interpolated into generated task definitions (.projen/tasks.json). The fix in version 0.103.0 requires upgrading and re-synthesizing the project to regenerate the corrected task definitions. Both vulnerabilities require upgrading to the fixed versions to mitigate the risks.
Potential Impact
CVE-2026-89065 could allow attackers with the ability to influence the generated file manifest to delete files and directories outside the intended project scope, potentially causing data loss or disruption. CVE-2026-89066 could enable attackers to execute arbitrary OS commands on developer machines or CI environments, potentially leading to full system compromise or unauthorized actions. Both vulnerabilities depend on context and attacker ability to influence project configuration or version-controlled files. No known exploits in the wild have been reported.
Mitigation Recommendations
For CVE-2026-89065, upgrade projen to version 0.101.37 or later; this fix is automatically applied by the runtime and re-synthesis is not required. Additionally, review the version control history of .projen/files.json for any entries that escape the project directory and remove them before running projen. For CVE-2026-89066, upgrade projen to version 0.103.0 or later and re-synthesize your project to regenerate the .projen/tasks.json file with corrected task definitions. Audit project configuration values and repository file names for shell metacharacters and remove or escape them prior to running projen. Upgrading alone is insufficient without re-synthesis due to the committed generated task definitions. It is recommended to upgrade to the latest projen version and ensure any derivative code incorporates these fixes.
CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection
Description
Two vulnerabilities were identified in the open-source tool projen affecting versions before 0.101.37 and 0.103.0. CVE-2026-89065 is a relative path traversal issue in the generated file manifest cleanup component that may allow attackers to delete files outside the project directory. CVE-2026-89066 is an OS command injection vulnerability in the task synthesis component that could enable arbitrary command execution on developer workstations or CI runners via shell metacharacters in project configuration or repository file names. Fixes are available in projen versions 0.101.37 and 0.103.0 respectively. Users must upgrade and, for CVE-2026-89066, re-synthesize their projects to regenerate safe task definitions.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
AWS identified two security issues in projen, an open-source project configuration tool. CVE-2026-89065 involves a relative path traversal vulnerability in the file manifest cleanup component in versions before 0.101.37, which could allow context-dependent attackers to recursively delete files and directories outside the project directory via crafted entries in the version-controlled generated file manifest (.projen/files.json). The fix is automatically applied by the projen runtime from version 0.101.37 onward. CVE-2026-89066 is an OS command injection vulnerability in the task synthesis component in versions before 0.103.0. This flaw allows context-dependent attackers to execute arbitrary OS commands on developer workstations or CI runners by injecting shell metacharacters into project configuration values or repository file names that are interpolated into generated task definitions (.projen/tasks.json). The fix in version 0.103.0 requires upgrading and re-synthesizing the project to regenerate the corrected task definitions. Both vulnerabilities require upgrading to the fixed versions to mitigate the risks.
Potential Impact
CVE-2026-89065 could allow attackers with the ability to influence the generated file manifest to delete files and directories outside the intended project scope, potentially causing data loss or disruption. CVE-2026-89066 could enable attackers to execute arbitrary OS commands on developer machines or CI environments, potentially leading to full system compromise or unauthorized actions. Both vulnerabilities depend on context and attacker ability to influence project configuration or version-controlled files. No known exploits in the wild have been reported.
Mitigation Recommendations
For CVE-2026-89065, upgrade projen to version 0.101.37 or later; this fix is automatically applied by the runtime and re-synthesis is not required. Additionally, review the version control history of .projen/files.json for any entries that escape the project directory and remove them before running projen. For CVE-2026-89066, upgrade projen to version 0.103.0 or later and re-synthesize your project to regenerate the .projen/tasks.json file with corrected task definitions. Audit project configuration values and repository file names for shell metacharacters and remove or escape them prior to running projen. Upgrading alone is insufficient without re-synthesis due to the committed generated task definitions. It is recommended to upgrade to the latest projen version and ensure any derivative code incorporates these fixes.
Technical Details
- Classification
- {"confidence":0.85,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-108-aws/","fetched":true,"fetchedAt":"2026-09-11T16:12:46.793Z","wordCount":345}
Threat ID: 6aa4287e91cc7f384860a7e0
Added to database: 09/11/2026, 16:12:46 UTC
Last enriched: 09/11/2026, 16:12:56 UTC
Last updated: 09/11/2026, 16:32:33 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.