CVE-2026-89066: OS command injection in the task synthesis component in projen

Published Sep 11, 2026
·
Updated

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and repository file names that are interpolated into generated task definitions.

To remediate this issue, users should upgrade to version 0.103.0 and then re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions. Upgrading alone is not sufficient because the generated task definition file is committed to the repository.

Affected Software

1 affected component
projen<0.103.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade projen to a version that resolves this vulnerability.

    Fixed in 0.103.0
  2. Operational

    After upgrading to projen 0.103.0, re-synthesize the project so that .projen/tasks.json is regenerated with the corrected task definitions (since the generated task definition file is committed to the repository).

Event History

Sep 11, 2026
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which environments are at risk?

Developer workstations and continuous integration runners are at risk when they execute generated projen task definitions containing unneutralized shell metacharacters. Exploitation is context-dependent and requires user interaction.

2

What input can an attacker use to trigger command execution?

An attacker may use shell metacharacters in project configuration values or repository file names when those values are interpolated into generated task definitions.

3

What remediation is required?

Upgrade projen to version 0.103.0 and re-synthesize the project to regenerate .projen/tasks.json with corrected task definitions. Upgrading the package alone is insufficient because the generated task definition file is committed to the repository.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203