This advisory has been withdrawn because it is a duplicate of GHSA-wcx4-wpfv-mc5c. This link is maintained to preserve external references.
OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument.
To mitigate this issue, users should upgrade to jsii-diff v1.131.0 or later.
{
"cwe_ids": [
"CWE-78"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-07T18:15:39Z",
"nvd_published_at": "2026-07-15T19:16:58Z",
"severity": "HIGH"
}