Just two characters short! Amazon Web Services' own GitHub repository was nearly breached, raising red flags for supply chain security

InfoQ
2026.01.29 22:00
portai
I'm PortAI, I can summarize articles.

Amazon Web Services released a security announcement confirming that some of its open-source GitHub repositories have a high-risk vulnerability called CodeBreach, which could lead to the introduction of malicious code and repository takeover. Wiz Security discovered that the ACTOR_ID filtering rules in some repositories were insufficient, allowing attackers to gain administrator privileges using predictable IDs. Affected repositories include AWS SDK for JavaScript v3, among others. Amazon Web Services has fixed the issue within 48 hours and stated that there are no similar errors in other repositories