CVE-2026-107332: Insecure Default File Permissions on Cached Credentials in AWS Toolkit for Visual Studio Code
Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files.
To mitigate this issue, users should upgrade to version 4.10.0 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AWS Toolkit for Visual Studio Codeto a version that resolves this vulnerability.Fixed in 4.10.0
Event History
Frequently Asked Questions
Who can exploit this issue?
A local user who can read the affected token cache files can obtain CodeCatalyst bearer tokens. The issue requires local access and low privileges; no user interaction is required.
Which installations are affected?
AWS Toolkit for Visual Studio Code versions before 4.10.0 are affected when using the CodeCatalyst connection handler. The vulnerable behavior creates world-readable token cache files.
What should teams do if they cannot upgrade immediately?
Restrict access to the affected system and prevent untrusted local users from reading the token cache files. Upgrade to AWS Toolkit for Visual Studio Code version 4.10.0 or later as soon as possible.
How can I determine whether credentials may have been exposed?
Check whether an affected pre-4.10.0 Toolkit installation used the CodeCatalyst connection handler and whether its token cache files were world-readable. If so, CodeCatalyst bearer tokens stored in those files may have been accessible to other local users.