#CodeCatalyst
AWS CodeCatalyst Blueprints SDK Hit by High-Severity Command Injection Flaw #AWSCodeCatalyst #AWSVulnerability #CodeCatalystBlueprints
AWS CodeCatalyst Blueprints SDK Hit by High-Severity Command Injection Flaw
There is a high-severity attack on Amazon CodeCatalyst blueprints that exploits an open-source framework for building them. This vulnerability has been reported by Amazon Web Services. This flaw affects the @amazon-codecatalyst/blueprints.blueprint npm package and can lead to the execution of arbitrary commands in environments operating blueprint resynthesis.  The Amazon CodeCatalyst blueprints serve as template documents for creating software development projects that can be reused. npm package that is affected provides the framework that blueprint authors use to construct these templates and is part of the open-source project AWS CodeCatalyst Blueprints.  During blueprint resynthesis, a vulnerability occurs in the process of determining which files an existing project may modify based on its .ownership-file, which is used to determine whether blueprints can modify them. Versions 0.3.155 and earlier handled the owner field of an entry containing a [local] merge strategy without adequate validation, which left it vulnerable to shell command interpretation.  A repository user with access to commit permissions could potentially use shell metacharacters to alter the affected field. In the context of resynthesis, those characters could be interpreted as commands by the operating system, allowing arbitrary commands to be executed in the resynthesis environment. The executed commands could consequently expose all privileges or credentials available in that environment.  Amazon has rated CVE-2026-85012 as 8.5 on the CVSS 4.0 scale, indicating that it is a high-severity vulnerability. Under CWE-78, which describes improper neutralization of special elements in operating system commands, this vulnerability has been classified as high severity. Amazon CodeCatalyst service deployments that utilize vulnerable versions of the blueprint framework are affected by this issue as opposed to the CodeCatalyst service itself.  As stated by Amazon, CodeCatalyst's resynthesis process operates in a separate environment with unique credentials for each project. Additionally, the service performs server-side validation to block merge strategy commands unless they conform to a restricted allowlist, including older blueprint versions.  AWS Releases Fix for CVE-2026-85012 It has been reported that Amazon has corrected this vulnerability in version 0.3.156 of @amazon-codecatalyst/blueprints.blueprint, which reverts to shell-based command interpretation and executes the relevant command directly in place of shell-based command interpretation. In addition, the patched release restricts accepted values to an allowlisted command format, closing the injection path identified in CVE-2026-85012.  Shell metacharacters are prevented from being interpreted during blueprint resynthesis as additional commands, closing the injection path identified in CVE-2026-85012. There are versions of the package 0.3.155 and earlier that are affected, so Amazon recommends upgrading to version 0.3.156, with forked and derivative implementations also requiring the appropriate security updates. There is no need for Amazon CodeCatalyst customers to respond to this vulnerability on the service-side.  Resynthesis jobs within the service are conducted in isolated environments assigned to specific projects, using scoped credentials. Server-side checks are also applied by AWS to reject [local] merge strategy commands that do not conform to the approved format. In addition, these protections apply when blueprints are published using versions of the framework prior to version 0.3.156.  The primary remediation concern is those projects or development environments that directly utilize the affected open-source framework following the implementation of the package-level fix. This updates the dependency, therefore removing the vulnerable shell execution behavior, and resolving the underlying issue of command injection described in CWE-78. By removing shell interpretation and enforcing an allowlisted command format, version 0.3.156 resolves the underlying command injection issue. Users who are currently using version 0.3.156 should take the necessary steps to update their SDK.
dlvr.it
September 5, 2026 at 4:57 PM
CVE-2026-85012 - Command Injection in AWS codecatalyst-blueprints. Arbitrary command execution via crafted .ownership-file. CVSS 8.0. Update to v0.3.156 now. #CVE #AWS #infosec

https://www.valtersit.com/cve/CVE-2026-85012/
September 4, 2026 at 1:14 AM
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
CVE ID : CVE-2026-85012

Published : Sept. 3, 2026, 6:17 p.m. | 20 minutes ago

Description : Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynth...
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in …
cvefeed.io
September 3, 2026 at 7:04 PM
• CodeCatalyst, closed to new customers since November 2025

ECS itself? Around since 2014, core API unchanged
It just f@#& works.
September 2, 2026 at 7:00 AM
• 𝗔𝗪𝗦 𝗖𝗼𝗽𝗶𝗹𝗼𝘁 𝗖𝗟𝗜, end of life June 2026.
• 𝗔𝗪𝗦 𝗣𝗿𝗼𝘁𝗼𝗻, end of life October 2026.
• 𝗔𝗪𝗦 𝗔𝗽𝗽 𝗥𝘂𝗻𝗻𝗲𝗿, no new customers since April 2026.
• 𝗖𝗼𝗱𝗲𝗖𝗮𝘁𝗮𝗹𝘆𝘀𝘁, no new customers since November 2025.

AWS thinks ECS has a complexity problem.
May 25, 2026 at 6:57 AM
CodeCatalyst?"

https://lckhd.eu/nrCc0J

#CodeCatalyst #DevTools (2/2)
March 26, 2026 at 11:19 AM
AWS CodeCatalyst実践入門 ――クラウドネイティブ開発を一冊で <佐藤 将> が、Kindleストアで販売開始されました。
5leaf.jp/kindle/B0FV3GHG74/#a...
『AWS CodeCatalyst実践入門』――クラウドネイティブ開発を一冊で
著者:佐藤 将(著) 個人出版 2026/1/2(金)配信
5leaf.jp
January 2, 2026 at 5:54 PM
Amazon CodeCatalyst の新規受付が終了するようなのでリポジトリを GitHub へ移行してみた | DevelopersIO https://dev.classmethod.jp/articles/codecatalyst-github-importer/

えー、CodeCatalystも使えなくなったの? んもー…
Amazon CodeCatalyst の新規受付が終了するようなのでリポジトリを GitHub へ移行してみた | DevelopersIO
dev.classmethod.jp
November 22, 2025 at 2:58 PM
AWS executed its largest service deprecation ever, killing 24 services at once. Four will force painful rewrites: Glacier API, S3 Object Lambda, Snowball Edge, and CodeCatalyst (AWS's embarrassingly failed GitHub competitor). Clearing out the "rotten fruit."
November 16, 2025 at 3:11 AM
🆕 AWS updates service availability: Some services moving to maintenance, others entering sunset, and a few ending support. Current users can continue, but migration planning advised. Visit AWS Product Lifecycle Page for details.

#AWS
AWS Service Availability Updates
After careful consideration, we’re announcing availability changes for a select group of AWS services and features. These changes fall into three lifecycle categories: Services and Capabilities moving to Maintenance Services moving to maintenance will no longer be accessible to new customers starting Nov 7, 2025. Current customers can continue using the service or feature while exploring alternative solutions. Amazon Cloud Directory Amazon CodeCatalyst Amazon CodeGuru Reviewer Amazon Fraud Detector Amazon Glacier Amazon S3 Object Lambda Amazon Workspaces Web Access Client for PCoIP (STXHD) AWS Application Discovery Service AWS HealthOmics - Variant and Annotation Store AWS IoT SiteWise Edge Data Processing Pack AWS IoT SiteWise Monitor AWS Mainframe Modernization Service AWS Migration Hub AWS Snowball Edge Compute Optimized AWS Snowball Edge Storage Optimized AWS Systems Manager - Change Manager AWS Systems Manager - Incident Manager AWS Thinkbox Deadline 10 .NET Modernization Tools Services Entering Sunset The following services are entering sunset, and we are announcing the date upon which we will end operations and support of the service. Customers using these services should click on the links below to understand the sunset timeline (typically 12 months), and begin planning migration to alternatives as recommended in the updated service web pages and documentation. Amazon FinSpace Amazon Lookout for Equipment AWS IoT Greengrass v1 AWS Proton Services Reaching End of Support The following services have reached end of support and are no longer available as of October 7, 2025. AWS Mainframe Modernization App Testing For customers affected by these changes, we've prepared comprehensive migration guides and our support teams are ready to assist with your transition. Visit AWS Product Lifecycle Page to learn more. or contact AWS Support.
aws.amazon.com
October 13, 2025 at 6:40 PM
AWS Service Availability Updates
After careful consideration, we’re announcing availability changes for a select group of AWS services and features. These changes fall into three lifecycle categories: Services and Capabilities moving to Maintenance Services moving to maintenance will no longer be accessible to new customers starting Nov 7, 2025. Current customers can continue using the service or feature while exploring alternative solutions. * Amazon Cloud Directory * Amazon CodeCatalyst * Amazon CodeGuru Reviewer * Amazon Fraud Detector * Amazon Glacier * Amazon S3 Object Lambda * Amazon Workspaces Web Access Client for PCoIP (STXHD) * AWS Application Discovery Service * AWS HealthOmics - Variant and Annotation Store * AWS IoT SiteWise Edge Data Processing Pack * AWS IoT SiteWise Monitor * AWS Mainframe Modernization Service * AWS Migration Hub * AWS Snowball Edge Compute Optimized * AWS Snowball Edge Storage Optimized * AWS Systems Manager - Change Manager * AWS Systems Manager - Incident Manager * AWS Thinkbox Deadline 10 * .NET Modernization Tools Services Entering Sunset The following services are entering sunset, and we are announcing the date upon which we will end operations and support of the service. Customers using these services should click on the links below to understand the sunset timeline (typically 12 months), and begin planning migration to alternatives as recommended in the updated service web pages and documentation. * Amazon FinSpace * Amazon Lookout for Equipment * AWS IoT Greengrass v1 * AWS Proton Services Reaching End of Support The following services have reached end of support and are no longer available as of October 7, 2025. * AWS Mainframe Modernization App Testing For customers affected by these changes, we've prepared comprehensive migration guides and our support teams are ready to assist with your transition. Visit AWS Product Lifecycle Page to learn more. or contact AWS Support.
dlvr.it
October 13, 2025 at 6:12 PM
AWS Service Availability Updates

AWS announces their quarterly "oops we built too many services" cleanup. Pour one out for CodeCatalyst, Fraud Detector, and 20 other products you didn't know existed and definitely weren't using. See you at re:Invent 2024!
October 13, 2025 at 6:09 PM
CodeCatalyst新規受付停止とか、採算が取れないのか知らないけど…AWSもGoogleと同じぐらいサービス継続についてはやっぱり信用できないな。
October 8, 2025 at 10:35 AM
📢 Sigo investigando #AWS #codecatalyst, dejo por aquí un post donde integro con un repositorio en #github y despliego un AWS #Cognito utilizando #terraform

olcortesb.hashnode.dev/integrando-c...
olcortesb.hashnode.dev
August 27, 2025 at 8:03 AM
📢🚨Nuevo blog #AWSEspanol en #devto: Probando AWS CodeCatalyst🚀 desde el AWS Builder ID 👷

#AWSCodeCatalyst #BuilderID #DevOps #CloudComputing #FreeTier
Probando AWS CodeCatalyst🚀 desde el AWS Builder ID 👷
Source: https://olcortesb.hashnode.dev/probando-aws-codecatalyst-desde-el-aws-builder-id En este...
ift.tt
August 8, 2025 at 8:43 AM
📢 NEW: #codecatalyst, como siempre que pruebo un nuevo servicio de #AWS, aprovecho de comentarlo con la comunidad y me dio elegido, siempre es dev.to/aws-espanol, esta oportunidad explico paso a paso como construir un proyecto en AWS codecatalyst
lnkd.in/dCkwwxzz
AWS Español — DEV Community Profile
dev.to
August 6, 2025 at 11:58 AM
GitHub vs AWS CodeCatalyst: Choosing the Right Platform for Modern Software Development Comparing two leading DevOps platforms for source control, CI/CD, and cloud-native development Continue readi...

#technology #coding #ai #artificial-intelligence #software-development

Origin | Interest | Match
GitHub vs AWS CodeCatalyst: Choosing the Right Platform for Modern Software Development
Comparing two leading DevOps platforms for source control, CI/CD, and cloud-native development
rajuhemanth456.medium.com
July 29, 2025 at 6:41 AM
🔧 למדו להקים סביבת פיתוח dbt עם AWS CodeCatalyst ו-Redshift! מדריך למתחילים עם Free Tier, אינטגרציה ל-VS Code ועוד #AWS #Data
Building a dbt Dev Environment with AWS CodeCatalyst and Redshift
community.aws
June 6, 2025 at 9:36 PM
ブログ投稿しました。
Amazon CodeCatalystは、GitHub Actionsの形式のワークフローを動かすことができますが、注意事項があるのでその内容を書いています。
すでに知っている記法が使えると言う魅力的な機能ですが、やっぱり気をつけるべき点はありましたね。
#AWS
blog.serverworks.co.jp/github-actio...
Amazon CodeCatalystが提供するGitHub Actionsのランタイム環境の注意点 - サーバーワークスエンジニアブログ
こんにちは。 アプリケーションサービス部、DevOps担当の兼安です。 今回はAmazon CodeCatalystで、GitHub Actionsのワークフローを動かす際、ランタイム環境に注意が必要なことをお話しします。 本記事のターゲット Amazon CodeCatalystとは GitHub Actionsで書いたワークフローをAmazon CodeCatalystで実行する方法 Code...
blog.serverworks.co.jp
May 12, 2025 at 8:36 AM
✍️ New blog post by Jacek Kościesza

Initial Requirements using Gherkin, GitHub, CodeCatalyst - FakeTube #1

#github #codecatalyst #youtube #clone
Initial Requirements using Gherkin, GitHub, CodeCatalyst - FakeTube #1
We are building FakeTube - a YouTube clone software engineering project using cloud-native and web...
dev.to
March 31, 2025 at 3:44 PM
記事書きました(正確には書いてありました)。

Amazon CodeCatalyst を使って Web サイトを EC2 にデプロイする手順
https://migiwa-ya.dev/articles/amazon-codecatalyst-deploy-to-ec2

#AWS #CodeCatalyst #CICD
Amazon CodeCatalyst を使って Web サイトを EC2 にデプロイする手順 - migiwa-ya.dev
Amazon CodeCatalyst と AWS CodeDeploy を使い、Web サイト(Laravel を想定)を EC2 にデプロイする手順のメモ。
migiwa-ya.dev
March 20, 2025 at 8:04 PM
✍️ New blog post by GargeeBhatnagar

App Creation in Generative AI Using AWS App Studio with AWS IAM Identity Center and Amazon CodeCatalyst

#awsiamidentitycenter #amazoncodecatalyst #awsappstudio #cloudwatch
App Creation in Generative AI Using AWS App Studio with AWS IAM Identity Center and Amazon CodeCatalyst
“ I have checked the documents of AWS to resolve the issue of app creation in generative ai using aws...
dev.to
March 9, 2025 at 10:14 AM