VDB

GCVE-110-NPM-2026-013781

GCVE-110-NPM-2026-013781
Advisory Published
Vulnetix · Advisory published July 2, 2026
[IOC-STIX-MATCH] Malicious domain datadoghq.com — referenced in cdk-insights/scripts.js — matched: AWS_SECRET_ACCESS_KEY=your-secret`},CLOUDWATCH_MISSING_LOG_GROUP:{message:"CloudWatch transport requires logGroupName option",solution:"Provide logGroupName in transport options or set CLOUDWATCH_LOG_GROUP environment variable",example:'logGroupName: "/aws/lambda/my-function"'},CLOUDWATCH_LOG_GROUP_

Weaknesses (CWE)

CWE-94Improper Control of Generation of Code ('Code Injection')CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
npmcdk-insights* (affected), * (affected), * (affected), * (affected)

References

advisory
web

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›