In plain language
What this advisory means
AWS Toolkit for Visual Studio Code, an extension used by developers to work with AWS services, had a security issue where a user's login token was saved in a file accessible by anyone on the same computer. This file was not deleted after use, risking unauthorized access by others sharing the machine. AWS fixed this in a recent update released in July 2026.
Technical explanation
How the issue affects the environment
CVE-2026-107332 concerns the CodeCatalyst connection handler within the AWS Toolkit for Visual Studio Code. The extension cached the user's CodeCatalyst bearer token in a file with world-readable permissions and failed to remove this file after the development session concluded. This flaw allowed any local user or process with file system access to read the cached token file and retrieve the bearer token, potentially enabling unauthorized actions under that user's identity. The issue is addressed in version 4.10.0, which sets the cache file permissions to owner-only and deletes the file upon stopping the Dev Environment.
Operational impact
Why teams should care
If exploited, an unauthorized local user can read sensitive authentication tokens from the system, leading to potential misuse of developer credentials to access or manipulate AWS resources without permission. This can result in data breaches, unauthorized resource usage, or compromise of the developer environment.
Immediate action
Upgrade to AWS Toolkit for Visual Studio Code version 4.10.0 or later. This version corrects file permissions on cached tokens and removes token files after use. For users unable to upgrade immediately, manually delete any 'codecatalyst.*.token' files found in the AWS Toolkit Visual Studio Code global storage directory after each development session.
Affected and fixed releases
Temporary risk reduction
Delete files named 'codecatalyst.*.token' located in the AWS Toolkit extension's Visual Studio Code global storage directory after each CodeCatalyst Dev Environment session to reduce exposure if upgrading is not yet possible.
Evidence and validation checklist
- AWS Security Bulletins official statement
- CVE-2026-107332 official identification
- Release notes of AWS Toolkit for Visual Studio Code version 4.10.0 specifying permission and cleanup changes
- Recommended mitigation and workaround guidelines from the vendor
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
