GHSA-wcx4-wpfv-mc5c: OS Command Injection

Published Aug 7, 2026
·
Updated

Summary

jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via this tool.

Impact jsii-diff supports downloading packages to compare directly from NPM, so that you can compare a proposed candidate version of your jsii package with an already-published version, by passing an argument that looks like npm:<package-specifier>. For example:

jsii-diff npm:my-package@latest .

By injecting a ; into the package-specifier part of that command, jsii-diff can be tricked into running shell commands. For example:

jsii-diff "npm:lodash; touch /tmp/123" .

This allows anyone that can control the command-line arguments to jsii-diff to run arbitrary commands with the same permissions as the jsii-diff command itself.

Patches This issue has been addressed in jsii-diff version 1.131.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds If you are unable to update, make sure only trusted actors can control the arguments passed to jsii-diff.

References If you have any questions or comments about this advisory, AWS asks that you contact AWS Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.

Affected Software

1 affected componentFixes available
npm/jsii-diff<1.131.0
1.131.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/jsii-diff to a version that resolves this vulnerability.

    Fixed in 1.131.0
  2. Upgrade

    Upgrade jsii-diff to a version that resolves this vulnerability.

    Fixed in 1.131.0
  3. Compensating control

    If you cannot upgrade, ensure only trusted actors can control the command-line arguments passed to jsii-diff (specifically the `npm:<package-specifier>` argument that jsii-diff accepts).

Event History

Aug 7, 2026
Advisory Published
via GitHub·06:15 PM
Data Sourced
via GitHub·06:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of GHSA-wcx4-wpfv-mc5c?

The severity of GHSA-wcx4-wpfv-mc5c is high, rated at 7.8.

2

What type of vulnerability is GHSA-wcx4-wpfv-mc5c?

GHSA-wcx4-wpfv-mc5c is classified as an OS Command Injection vulnerability.

3

How do I fix GHSA-wcx4-wpfv-mc5c?

To fix GHSA-wcx4-wpfv-mc5c, update jsii-diff to the latest version that addresses this command injection issue.

4

What consequences could arise from GHSA-wcx4-wpfv-mc5c?

Exploiting GHSA-wcx4-wpfv-mc5c could allow an attacker to execute arbitrary shell commands on the system.

5

Which software is affected by GHSA-wcx4-wpfv-mc5c?

The affected software for GHSA-wcx4-wpfv-mc5c is npm/jsii-diff.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203