aws-cdk-lib: bundled @aws-cdk/asset-node-proxy-agent-v6@2.1.1 dependant package vulnerability CVE-2026-39983
- Dominant language
- TypeScript
- Stars
- 12.9k
- Forks
- 4.6k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 83
Description
### Describe the bug
`aws-cdk-lib@2.248.0` bundles `@aws-cdk/asset-node-proxy-agent-v6@2.1.1` which uses `basic-ftp@5.2.0`
Security scanning is flagging this against CVE-2026-39983. See https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-chqc-8p9q-pq6q
I am not sure if the bundled proxy agent is susceptible to this issue. However basic-ftp@5.2.1 is listed as a patched version.
### Regression Issue
- [ ] Select this option if this issue appears to be a regression.
### Last Known Working CDK Library Version
_No response_
### Expected Behavior
n/a
### Current Behavior
n/a
### Reproduction Steps
Install aws-cdk-lib@2.248.0 & scan dependencies
### Possible Solution
_No response_
### Additional Information/Context
_No response_
### AWS CDK Library version (aws-cdk-lib)
2.248.0
### AWS CDK CLI version
2.1118.0
### Node.js Version
24
### OS
Linux
### Language
TypeScript
### Language Version
_No response_
### Other information
_No response_
Contributor guide
Research direction
Start by installing aws-cdk-lib@2.248.0 and scanning dependencies, then inspect how @aws-cdk/asset-node-proxy-agent-v6@2.1.1 bundles basic-ftp@5.2.0. Confirm whether the bundle is affected by CVE-2026-39983 and verify that the dependency is updated to patched basic-ftp@5.2.1.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100