Skip to content

AWS zero day exploited to access codebase for its AI assistant

AWS has now "included additional protections against memory dumps within container builds..."

AWS CodeBuild vulnerability CVE-2025-8217 exploited

See also our updated, more detailed story of July 29 .

A hacker accessed two AWS source code repositories by exploiting a zero day in its AWS CodeBuild managed service, AWS confirmed early Saturday.

That vulnerability, now allocated CVE-2025-8217, let an attacker “extract the source code repository (e.g. GitHub, BitBucket, or GitLab) access token through a memory dump within the CodeBuild build environment,” it said.

This content is for members only

Subscribe
Add The Stack on Google