A AegiFlow
HIGHCVSS 8.4EPSS 0.6%

CVE-2026-15895

jsii-diff: Command Injection via npm: package argument

Published
2026-08-07
Modified
2026-08-07
EPSS percentile
47%
Aliases
GHSA-wcx4-wpfv-mc5c
Sources
github-advisory

Summary

## Summary jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via this tool. ## Impact jsii-diff supports downloading packages to compare directly from NPM, so that you can compare a proposed candidate version of your jsii package with an already-published version, by passing an argument that looks like `npm: `. For example: ``` jsii-diff npm:my-package@latest . ``` By injecting a `;` into the `package-specifier` part of that command, jsii-diff can be tricked into running shell commands. For example: ``` jsii-diff "npm:lodash; touch /tmp/123" . ``` This allows anyone that can control the command-line arguments to jsii-diff to run arbitrary commands with the same permissions as the jsii-diff command itself. ## Patches This issue has been addressed in jsii-diff version 1.131.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ## Workarounds If you are unable to update, make sure only trusted actors can control the arguments passed to jsii-diff. ## References If you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmjsii-diff1.131.0

Remediation: Upgrade to 1.131.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.