projen vulnerabilities
CVEs whose affected-version data names the projen package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-89066High· 7.8Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous int…
Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous int…
▾ TwilightAWS · projenEPSS 0.16%via NVD
CVE-2026-89065High· 7.1Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the…
Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the…
▾ TwilightAWS · projenEPSS 0.15%via NVD
CVE-2021-21423Medium· 6.8PoCRebuild-bot workflow may allow unauthorised repository modifications
Rebuild-bot workflow may allow unauthorised repository modifications
▾ Twilightprojen · projenEPSS 1.4%via OSV