← All Advisories

Shell Metacharacters in .ownership-file's Owner Field Reach popen in Amazon CodeCatalyst Blueprint Resynthesis, Enabling Command Injection for Repository Committers

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-85012

Key Details

CVECVE-2026-85012
CVSS Score / Version8.0 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry in a crafted .ownership-file.

Version 0.3.156 removes shell interpretation of the owner field, running the command directly rather than through a shell, and rejects values outside an allowlisted command form. This eliminates shell metacharacter command injection. To remediate this issue, users should upgrade to version 0.3.156 or later.

No action is required for use of the Amazon CodeCatalyst service. Resynthesis runs in an isolated per-project environment with scoped credentials, and the service applies server-side validation there that rejects [local] merge strategy commands outside a restricted allowlisted form, including for blueprint versions published before 0.3.156. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-85012
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-85012