CVE-2026-15895: OS command injection in jsii-diff in AWS jsii
Bulletin ID: 2026-057-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 12:00 PM PDT Description: jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. We identified CVE-2026-15895, an issue where specially formatted command line arguments can be used to execute shell commands via this tool. Impacted versions: < 1.131.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Specially formatted command line arguments can be used to execute shell commands via jsii-diff.
- Who is affected
- Users of jsii-diff versions below 1.131.0.
- Urgency
- Attention is required to prevent potential exploitation.
- Action
- Update to version 1.131.0 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch jsii-diff
Get an email when a new jsii-diff advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-057-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-158951.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15895 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for OS command injection
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-82004: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements use…nvd · 2026-09-08
- highCVE-2026-81349: Improper neutralization of special elements used in an os command ('os command injection') in …nvd · 2026-09-08
- criticalGHSA-xp7j-h7jc-4w8p: Semaphore U: OS Command Injectionghsa · 2026-09-08
- highCVE-2026-61517: Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability …nvd · 2026-09-08
- criticalCVE-2026-71376: OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosmi…nvd · 2026-09-08
- highCVE-2026-53932: laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to ver…nvd · 2026-09-04
More from AWS Security Bulletins
- unknownCVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards2026-09-08
- unknownCVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs pos…2026-09-04
- unknownCVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server2026-09-04
- unknownCVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java2026-09-04
- unknownCVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver2026-09-04