Intel

AIKIDO-2025-10249

aws-cdk-lib is vulnerable to Incorrect Execution-Assigned Permissions

Incorrect Execution-Assigned Permissions Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 18, 2025

21

Low Risk

This Affects:

JSaws-cdk-lib
2.0.0 - 2.189.0
Fixed in 2.189.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to incorrect permission assignment when using Aspects with the default execution order. An attacker can assign DEFAULT permissions to a custom Aspect, which may be overridden by a built-in CDK method using MUTATING permissions. This can cause the custom Aspect to have either fewer or, in permissive environments, more permissions than expected.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

aws-cdk-lib is vulnerable to Incorrect Execution-Assigned Permissions in versions 2.0.0 - 2.189.0.

How to fix this

Upgrade the aws-cdk-lib library to the patch version.