LocalStack is a local AWS emulation framework used in development and testing environments to simulate AWS services without external cloud dependencies. Its durable vulnerability signal centers on certificate validation, cross-site scripting, and OS command injection issues, which reflect the complexity of parsing and validating user-supplied configuration in a service-mocking context. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Localstack over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32090CRITICAL The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter. | May 7, 2021 | 9.8 | 29 | NO | NO |
CVE-2023-48054HIGH Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack. | Nov 16, 2023 | 7.4 | 21 | NO | NO |
CVE-2021-32091MEDIUM A Cross-site scripting (XSS) vulnerability exists in StackLift LocalStack 0.12.6. | May 7, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Localstack.
Media articles that mention a CVE ID that affects a product developed by Localstack — matched by CVE ID, not by vendor name.