Summary
At main commit e6cf018, the enterprise-agentic-ai-platform-blueprint lockfile resolves aws-cdk-lib to 2.251.0, and a lockfile-only audit reports 7 vulnerable packages: 5 high, 1 moderate, and 1 low.
The highest-priority direct finding is GHSA-vcrf-j523-4mrf / CVE-2026-13760, an OS command-injection issue in NodejsFunction Docker bundling:
- affected:
aws-cdk-lib < 2.260.0
- fixed:
aws-cdk-lib 2.260.0
- locked here:
aws-cdk-lib 2.251.0
- severity: high (CVSS 7.3)
This is a build/deployment-toolchain risk. Exploitation requires control of dependency version strings processed while Docker-based bundling is used with nodeModules; this finding alone is not evidence of remote exploitability in a deployed workload.
Audit findings
| Package |
Severity |
Relationship |
aws-cdk-lib |
High |
Direct dependency; also has a low-severity advisory |
fast-uri |
High |
Transitive |
brace-expansion |
High |
Transitive |
browserslist |
High |
Transitive |
js-yaml |
High |
Transitive |
baseline-browser-mapping |
Moderate |
Transitive |
@babel/core |
Low |
Transitive |
Existing remediation PRs
Dependabot has already opened several relevant updates:
This issue is intended to track verification and closure across those PRs, rather than duplicate them.
Acceptance criteria
Verification performed
The finding was reproduced with a lockfile-only audit. No application code, tests, CDK synthesis, deployment, or AWS resources were run as part of this verification.
Summary
At
maincommite6cf018, theenterprise-agentic-ai-platform-blueprintlockfile resolvesaws-cdk-libto2.251.0, and a lockfile-only audit reports 7 vulnerable packages: 5 high, 1 moderate, and 1 low.The highest-priority direct finding is GHSA-vcrf-j523-4mrf / CVE-2026-13760, an OS command-injection issue in
NodejsFunctionDocker bundling:aws-cdk-lib < 2.260.0aws-cdk-lib 2.260.0aws-cdk-lib 2.251.0This is a build/deployment-toolchain risk. Exploitation requires control of dependency version strings processed while Docker-based bundling is used with
nodeModules; this finding alone is not evidence of remote exploitability in a deployed workload.Audit findings
aws-cdk-libfast-uribrace-expansionbrowserslistjs-yamlbaseline-browser-mapping@babel/coreExisting remediation PRs
Dependabot has already opened several relevant updates:
aws-cdk-lib2.251.0 → 2.265.0brace-expansion1.1.14 → 1.1.18browserslist4.28.2 → 4.28.9baseline-browser-mapping2.10.24 → 2.11.22js-yaml3.14.2 → 3.15.2This issue is intended to track verification and closure across those PRs, rather than duplicate them.
Acceptance criteria
aws-cdk-libresolves to at least2.260.0(the current PR targets2.265.0).npm audit --package-lock-onlyand confirm there are no remaining high or critical findings.Verification performed
The finding was reproduced with a lockfile-only audit. No application code, tests, CDK synthesis, deployment, or AWS resources were run as part of this verification.