Aws · Aws Cdk Cli · CVE-2025-2598
**Name of the Vulnerable Software and Affected Versions**
AWS CDK CLI versions prior to 2.178.2
**Description**
The issue arises when the AWS CDK CLI is used with a credential plugin that returns an expiration property with the retrieved AWS credentials, causing the credentials to be printed to the console output.
**Recommendations**
For versions prior to 2.178.2, upgrade to version 2.178.2 or later to resolve the issue. Additionally, ensure any forked or derivative code is patched to incorporate the new fixes.