{"id":"GHSA-8wj8-cfxr-9374","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8wj8-cfxr-9374","summary":"AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance","details":"### Description of Vulnerability: \nAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.\n\nAWS recommends that customers upgrade to the following version:  AWS NodeJS Wrapper to v2.0.1.\n\n\n### Source of Vulnerability Report:\nAllistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com)\n\n\n### Affected products & versions: \nAWS NodeJS Wrapper < 2.0.1.\n\n\n### Platforms: \nMacOS/Windows/Linux","published":"2025-11-13T22:22:37Z","modified":"2026-02-04T02:37:03.636228Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"aws-advanced-nodejs-wrapper","fixedVersion":"2.0.1"}],"fix":{"url":"https://github.com/aws/aws-advanced-nodejs-wrapper/pull/574","label":"aws/aws-advanced-nodejs-wrapper#574"},"references":[{"type":"WEB","url":"https://github.com/aws/aws-advanced-nodejs-wrapper/security/advisories/GHSA-8wj8-cfxr-9374"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-nodejs-wrapper/pull/574"},{"type":"PACKAGE","url":"https://github.com/aws/aws-advanced-nodejs-wrapper"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-nodejs-wrapper/releases/tag/2.0.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-04T02:37:03.636228Z"}}