@aws/lsp-codewhisperer vulnerabilities
CVEs whose affected-version data names the @aws/lsp-codewhisperer package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-12957HighLanguage Servers for AWS Vulnerable to Arbitrary Code Execution
Language Servers for AWS Vulnerable to Arbitrary Code Execution
▾ Twilightaws · @aws/lsp-codewhispererEPSS 0.18%via GHSA
CVE-2026-12958High· 7.8Language Servers for AWS vulnerable to arbitrary file write
Language Servers for AWS vulnerable to arbitrary file write
▾ Twilightaws · @aws/lsp-codewhispererEPSS 0.19%via GHSA