Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code

AWS Toolkit for Visual Studio Code, an extension used by developers to work with AWS services, had a security issue where a user's login token was saved in a file accessible by anyone on the same computer. This file was not deleted after use, risking unauthorized access by others sharing the machine. AWS fixed this in a recent update released in July 2026.

QCS published 9/10/2026, 7:00:17 pm ISTVendor disclosure 8/10/2026, 11:13:09 pm ISTVerified 9/10/2026, 7:00:17 pm ISTRevision 1

In plain language

What this advisory means

AWS Toolkit for Visual Studio Code, an extension used by developers to work with AWS services, had a security issue where a user's login token was saved in a file accessible by anyone on the same computer. This file was not deleted after use, risking unauthorized access by others sharing the machine. AWS fixed this in a recent update released in July 2026.

Technical explanation

How the issue affects the environment

CVE-2026-107332 concerns the CodeCatalyst connection handler within the AWS Toolkit for Visual Studio Code. The extension cached the user's CodeCatalyst bearer token in a file with world-readable permissions and failed to remove this file after the development session concluded. This flaw allowed any local user or process with file system access to read the cached token file and retrieve the bearer token, potentially enabling unauthorized actions under that user's identity. The issue is addressed in version 4.10.0, which sets the cache file permissions to owner-only and deletes the file upon stopping the Dev Environment.

Operational impact

Why teams should care

If exploited, an unauthorized local user can read sensitive authentication tokens from the system, leading to potential misuse of developer credentials to access or manipulate AWS resources without permission. This can result in data breaches, unauthorized resource usage, or compromise of the developer environment.

Immediate action

Upgrade to AWS Toolkit for Visual Studio Code version 4.10.0 or later. This version corrects file permissions on cached tokens and removes token files after use. For users unable to upgrade immediately, manually delete any 'codecatalyst.*.token' files found in the AWS Toolkit Visual Studio Code global storage directory after each development session.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versions4.10.0

Temporary risk reduction

Delete files named 'codecatalyst.*.token' located in the AWS Toolkit extension's Visual Studio Code global storage directory after each CodeCatalyst Dev Environment session to reduce exposure if upgrading is not yet possible.

Evidence and validation checklist

  • AWS Security Bulletins official statement
  • CVE-2026-107332 official identification
  • Release notes of AWS Toolkit for Visual Studio Code version 4.10.0 specifying permission and cleanup changes
  • Recommended mitigation and workaround guidelines from the vendor

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source