GHSA-4h3p-r584-fm85MediumCVSS 4.7
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-86516
- https://github.com/elenavanengelenmaslova/mocknest-serverless/pull/254
- https://github.com/elenavanengelenmaslova/mocknest-serverless/commit/6ab3147282d867c1993f995272750db091c2290b
- https://github.com/elenavanengelenmaslova/mocknest-serverless
- https://vuldb.com/cve/CVE-2026-86516
- https://vuldb.com/submit/908568
- https://vuldb.com/vuln/399670
- https://vuldb.com/vuln/399670/cti
- https://github.com/advisories/GHSA-4h3p-r584-fm85