HIGH 7.8 GitHub
CVE-2026-15895
jsii-diff: Command Injection via npm: package argument
## Summary
jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via this tool.
## Impact
jsii-diff supports downloading packages to compare directly from NPM, so that you can compare a proposed candidate version of your jsii package with an already-published version, by passing an
Affected Products
- npm/jsii-diff < 1.131.0
References
- https://github.com/advisories/GHSA-wcx4-wpfv-mc5c
- https://github.com/aws/jsii/security/advisories/GHSA-wcx4-wpfv-mc5c
- https://nvd.nist.gov/vuln/detail/CVE-2026-15895
- https://aws.amazon.com/security/security-bulletins/2026-057-aws
This high severity vulnerability with a CVSS score of 7.8 was published on 2026-08-07 via GitHub. Affected: npm/jsii-diff < 1.131.0.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.