CVE-2026-107332: Insecure Default File Permissions on Cached Credentials in AWS Toolkit for Visual Studio Code

Published Oct 8, 2026
·
Updated

Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files.

To mitigate this issue, users should upgrade to version 4.10.0 or later.

Affected Software

1 affected component
AWS AWS Toolkit for Visual Studio Code<4.10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade AWS Toolkit for Visual Studio Code to a version that resolves this vulnerability.

    Fixed in 4.10.0

Event History

Oct 8, 2026
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A local user who can read the affected token cache files can obtain CodeCatalyst bearer tokens. The issue requires local access and low privileges; no user interaction is required.

2

Which installations are affected?

AWS Toolkit for Visual Studio Code versions before 4.10.0 are affected when using the CodeCatalyst connection handler. The vulnerable behavior creates world-readable token cache files.

3

What should teams do if they cannot upgrade immediately?

Restrict access to the affected system and prevent untrusted local users from reading the token cache files. Upgrade to AWS Toolkit for Visual Studio Code version 4.10.0 or later as soon as possible.

4

How can I determine whether credentials may have been exposed?

Check whether an affected pre-4.10.0 Toolkit installation used the CodeCatalyst connection handler and whether its token cache files were world-readable. If so, CodeCatalyst bearer tokens stored in those files may have been accessible to other local users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203