CVE-2026-13769 Affecting localstack package, versions <4.14.0-r20


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.12% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-LOCALSTACK-18585153
  • published8 Aug 2026
  • disclosed1 Jul 2026

Introduced: 1 Jul 2026

CVE-2026-13769  (opens in a new tab)

How to fix?

Upgrade Chainguard localstack to version 4.14.0-r20 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream localstack package and not the localstack package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the same host to read credentials written by certain CLI subcommands (aws codeartifact login, aws iam create-virtual-mfa-device, aws deploy register).

To remediate this issue, users should upgrade to AWS CLI 1.44.78 (v1) or 2.34.29 (v2) or later.

CVSS Base Scores

version 3.1