Skip to main content

CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code

Bulletin ID: 2026-129-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/08/2026 10:30 AM PDT

Description:

AWS Toolkit for Visual Studio Code is an open source extension that lets developers work with AWS services, including Amazon CodeCatalyst, from within Visual Studio Code. We identified CVE-2026-107332, an issue in the CodeCatalyst connection handler. When a user connected to a CodeCatalyst Dev Environment, the extension cached the user's CodeCatalyst bearer token to a file with world-readable permissions and did not remove the file after the session ended. A local user or process on the same machine with access to the file system was able to read this file and obtain the bearer token.

Impacted versions: < 4.10.0

Resolution:

This issue has been addressed in AWS Toolkit for Visual Studio Code version 4.10.0, released on July 9, 2026. Version 4.10.0 writes the token cache file with owner-only permissions and deletes it when the Dev Environment is stopped. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

Users who cannot upgrade immediately can delete any files named codecatalyst..token in the AWS Toolkit extension's Visual Studio Code global storage directory after each session.

References:


Please email aws-security@amazon.com with any security questions or concerns.