logo

CodeBreach: Missing Regex Anchors Exposed AWS Console to Takeover

ID: 7879700f-82ec-5521-8e9e-c95db50ec756

STIX ID: report--7879700f-82ec-5521-8e9e-c95db50ec756

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-17

Date Updated: 2026-04-23

Author: Ddos

...
...

Wiz Research disclosed “CodeBreach,” a critical supply-chain vulnerability in AWS CodeBuild where a missing ^ and $ in an ACTOR_ID regex allow-list let accounts with “superstring” GitHub IDs trigger privileged builds; researchers created such an account, bypassed the filter, and extracted credentials that could enable malicious code injection into the AWS JavaScript SDK. AWS patched the regex and hardening measures within 48 hours and reported no customer impact, while recommending organizations review CI/CD build gate configurations to prevent untrusted contributions from triggering privileged pipelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.