@aws/lsp-codewhisperer
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @aws/lsp-codewhispererpage 1 of 1
- CVE-2026-12957HIGHCVSS 7.8EG 7.8fixed in 0.0.1132026-06-23
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the proje…
- CVE-2026-12958HIGHCVSS 7.8EG 7.8fixed in 0.0.1172026-06-23
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file…
Check whether @aws/lsp-codewhisperer is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @aws/lsp-codewhisperer CVEs against the assets you own.
Book a Demo →