{"id":"PYSEC-2026-1205","summary":"AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance ","details":"### Description of Vulnerability:\n\nAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.\n\nAWS recommends customers upgrade to the following versions:  AWS Python Wrapper to v1.4.0\n\n\n### Source of Vulnerability Report: \nAllistair Ishmael Hakim \u003callistair.hakim@gmail.com\u003e\n\n\n### Affected products & versions: \nAWS Python Wrapper \u003c 1.4.0\n\n\n### Platforms: \nMacOS/Windows/Linux","aliases":["CVE-2025-12967","GHSA-4jvf-wx3f-2x8q"],"modified":"2026-07-07T17:46:32.809717645Z","published":"2026-07-07T16:03:10.351969Z","references":[{"type":"WEB","url":"https://github.com/aws/aws-advanced-go-wrapper/security/advisories/GHSA-7wq2-32h4-9hc9"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-jdbc-wrapper/security/advisories/GHSA-7xw4-g7mm-r4hh"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-python-wrapper/security/advisories/GHSA-4jvf-wx3f-2x8q"},{"type":"WEB","url":"https://github.com/aws/aws-pgsql-odbc/security/advisories/GHSA-q327-fgm8-7mxf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12967"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-python-wrapper/pull/1007"},{"type":"WEB","url":"https://aws.amazon.com/security/security-bulletins/AWS-2025-028"},{"type":"PACKAGE","url":"https://github.com/aws/aws-advanced-python-wrapper"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-python-wrapper/releases/tag/1.4.0"},{"type":"PACKAGE","url":"https://pypi.org/project/aws-advanced-python-wrapper"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4jvf-wx3f-2x8q"}],"affected":[{"package":{"name":"aws-advanced-python-wrapper","ecosystem":"PyPI","purl":"pkg:pypi/aws-advanced-python-wrapper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.0"}]}],"versions":["1.0.0","1.1.0","1.1.1","1.2.0","1.3.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/aws-advanced-python-wrapper/PYSEC-2026-1205.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}