{"id":"GHSA-8wj8-cfxr-9374","summary":"AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance","details":"### Description of Vulnerability: \nAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.\n\nAWS recommends that customers upgrade to the following version:  AWS NodeJS Wrapper to v2.0.1.\n\n\n### Source of Vulnerability Report:\nAllistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com)\n\n\n### Affected products & versions: \nAWS NodeJS Wrapper \u003c 2.0.1.\n\n\n### Platforms: \nMacOS/Windows/Linux","modified":"2026-02-04T02:37:03.636228Z","published":"2025-11-13T22:22:37Z","related":["CVE-2025-12967"],"database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-470"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-11-13T22:22:37Z"},"references":[{"type":"WEB","url":"https://github.com/aws/aws-advanced-nodejs-wrapper/security/advisories/GHSA-8wj8-cfxr-9374"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-nodejs-wrapper/pull/574"},{"type":"PACKAGE","url":"https://github.com/aws/aws-advanced-nodejs-wrapper"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-nodejs-wrapper/releases/tag/2.0.1"}],"affected":[{"package":{"name":"aws-advanced-nodejs-wrapper","ecosystem":"npm","purl":"pkg:npm/aws-advanced-nodejs-wrapper"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-8wj8-cfxr-9374/GHSA-8wj8-cfxr-9374.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}