CVE-2026-107332
MEDIUM
NVD
CVSS Score
5.5
Severity
MEDIUM
Published
Oct 08, 2026
Vendor
unknown
Description
Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cache files. To mitigate this issue, users should upgrade to version 4.10.0 or later.