Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files.
To mitigate this issue, users should upgrade to version 4.10.0 or later.
{
"cna_assigner": "AMZN",
"cwe_ids": [
"CWE-276",
"CWE-459"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107332.json"
}