What is CVE-2026-16763?
This critical vulnerability in the localstack serverless-localstack plugin up to version 1.4.0 allows OS command injection via the `custom.localstack.docker.compose_file` configuration argument. Users must urgently update to the latest plugin version and strictly sanitize any user-supplied configuration values.
Azərbaycanca: Bu kritik zəiflik localstack serverless-localstack plagininin 1.4.0-a qədər olan versiyalarında `custom.localstack.docker.compose_file` konfiqurasiya arqumenti vasitəsilə OS command injection hücumuna imkan verir. Təcili olaraq plaginin ən son versiyasına yenilənməli və istifadəçi tərəfindən təmin edilən konfiqurasiya dəyərləri ciddi şəkildə yoxlanılmalıdır.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which versions of the serverless-localstack plugin are affected by CVE-2026-16763?
The vulnerability covers the localstack serverless-localstack plugin up to version 1.4.0.
Which configuration argument is used to exploit CVE-2026-16763?
The vulnerability allows OS command injection via the `custom.localstack.docker.compose_file` configuration argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.