Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-16763 1 Localstack 1 Serverless-localstack 2026-07-24 5.3 Medium
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2023-48054 1 Localstack 1 Localstack 2024-11-21 7.4 High
Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
CVE-2021-32091 1 Localstack 1 Localstack 2024-11-21 6.1 Medium
A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6.
CVE-2021-32090 1 Localstack 1 Localstack 2024-11-21 9.8 Critical
The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.