CVE-2026-12958highCWE-61

CVE-2026-12958: fallo de gravedad alta en Amazon Web Services Language Servers for AWS

Arbitrary file write in Language Servers for AWS

Publicada el

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 8.5epss 0.2%
probabilidad de explotación
0.2%top 92% de las CVE
explotación observada
noninguna fuente lo reporta
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users should upgrade to version 1.69.0 or higher.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVEs relacionadas — Amazon Web Services Language Servers for AWS

En el mismo producto, de las más peligrosas a las menos.