CVE-2026-11417 is an OS command injection vulnerability in the NodejsFunction local bundling pipeline of aws-cdk-lib before 2.245.0, and before 2.246.0 on Windows. During local Lambda bundling, attacker-controlled values in one or more bundling properties—externalModules, define, loader, inject, or esbuildArgs—may be incorporated into shell command execution without sufficient neutralization of shell metacharacters. If a threat actor can influence these properties in a CDK application, they may inject arbitrary shell syntax and cause unintended commands to execute on the host running the AWS CDK toolchain.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real proof-of-concept exploit for CVE-2026-11417, a command injection vulnerability in AWS CDK's NodejsFunction bundling logic in aws-cdk-lib versions prior to 2.245.0. The repo is small and focused: a top-level README explains the vulnerability, impact, and patch details; the poc/ directory contains runnable TypeScript code plus a minimal Lambda handler and package.json pinned to vulnerable aws-cdk-lib 2.244.0. The main exploit logic is in poc/app.ts. It creates a CDK stack with a NodejsFunction whose bundling.externalModules array contains a malicious string: 'foo & echo CVE-2026-11417 PWNED > ../pwned.txt'. In vulnerable versions, NodejsFunction interpolates this value into a shell command used for local esbuild bundling. Because the command is executed through a shell, the '&' metacharacter causes command separation and arbitrary OS command execution on the host running app.synth()/cdk synth. The provided payload is benign and demonstrative: it writes a marker file ../pwned.txt. Exploit capability: host-level command execution during CDK synthesis/build time, which makes this especially relevant to developer workstations and CI/CD runners. The README also documents broader abuse potential, including supply-chain delivery through malicious third-party CDK constructs and possible credential exfiltration. This is not a scanner or detector; it is an operational PoC with a hardcoded payload demonstrating successful exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.