An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.
AWS recommends customers upgrade to the following versions: AWS Python Wrapper to v1.4.0
Allistair Ishmael Hakim allistair.hakim@gmail.com
AWS Python Wrapper < 1.4.0
MacOS/Windows/Linux
{
"severity": "HIGH",
"nvd_published_at": "2025-11-10T18:16:06Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-470"
],
"github_reviewed_at": "2025-11-13T22:22:07Z"
}