VulnSea

research_and_engineering_studio vulnerabilities

CVEs whose affected-version data names the research_and_engineering_studio package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-5709High· 8.8
5mo ago

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via craft…

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via craft…

Twilightamazon · research_and_engineering_studioEPSS 1.1%via NVD
CVE-2026-5708High· 8.8
5mo ago

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual…

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual…

Twilightamazon · research_and_engineering_studioEPSS 0.84%via NVD
CVE-2026-5707High· 8.8
5mo ago

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…

Twilightamazon · research_and_engineering_studioEPSS 0.99%via NVD
research_and_engineering_studio vulnerabilities (CVEs) · VulnSea