Summary
Bulletin ID: 2026-129-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/08/2026 10:30 PM PDT
Description:
AWS Toolkit for Visual Studio Code is an open source extension that lets developers work with AWS services, including Amazon CodeCatalyst, from within Visual Studio Code. We identified CVE-2026-107332, an issue in the CodeCatalyst connection handler.
When a user connected to a CodeCatalyst Dev Environment, the extension cached the user's CodeCatalyst bearer token to a file with world-readable permissions and did not remove the file after the session ended. A local user or process on the same machine with access to the file system was able to read this file and obtain the bearer token.
Impacted versions: < 4.10.0
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Products covered
A separate affected-products list was not included in the collected bulletin.
Remediation
Separate remediation guidance was not included in the collected bulletin.
CVEs in this advisory 1
Updates
- Published by AWS
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.
- Confirmed at the source
Our collector saw this advisory during a later source check.