AWS Security ChangesHomeSearch

AWS cdk: CDK v2 security: warn against deploying untrusted cloud assemblies

Service: cdk · 2026-09-27 · Documentation medium

File: cdk/v2/guide/security.md · Type: supply-chain

Summary

Added guidance in the CDK security best-practices topic stating that cloud assemblies (the cdk.out directory) can be deployed from external sources, and that you should only deploy a cloud assembly you produced yourself or that comes from a trusted source.

Security assessment

Documents a real supply-chain risk (deploying an attacker-supplied synthesized template/artifact), recommending trust boundaries for cloud assemblies; it is general hardening guidance rather than remediation of a named vulnerability or CVE, so it counts as security documentation.

Evidence

+Similarly, you should not deploy cloud assemblies from sources that you do not trust. Synthesizing a CDK app produces a cloud assembly (the `cdk.out` directory by default). It’s possible to deploy a previously synthesized cloud assembly from a different source; for example, `cdk deploy --app /downloaded/file/path/cdk.out`. Only deploy a cloud assembly that you produced yourself or that comes from a trusted source.

Diff

diff --git a/cdk/v2/guide/security.md b/cdk/v2/guide/security.md
index 42fd7ed8f..216a6032e 100644
--- a//cdk/v2/guide/security.md
+++ b//cdk/v2/guide/security.md
@@ -38,0 +39,2 @@ You should not use CDK in an environment where untrusted authors write parts of
+Similarly, you should not deploy cloud assemblies from sources that you do not trust. Synthesizing a CDK app produces a cloud assembly (the `cdk.out` directory by default). It’s possible to deploy a previously synthesized cloud assembly from a different source; for example, `cdk deploy --app /downloaded/file/path/cdk.out`. Only deploy a cloud assembly that you produced yourself or that comes from a trusted source.
+