VDB
Sign up
HIGH8.0

PYSEC-2026-1205

AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Quick fix

PYSEC-2026-1205 — aws-advanced-python-wrapper: upgrade to the fixed version with the command below.

pip install --upgrade 'aws-advanced-python-wrapper>=1.4.0'

Details

### Description of Vulnerability:

An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.

AWS recommends customers upgrade to the following versions: AWS Python Wrapper to v1.4.0

### Source of Vulnerability Report: Allistair Ishmael Hakim <allistair.hakim@gmail.com>

### Affected products & versions: AWS Python Wrapper < 1.4.0

### Platforms: MacOS/Windows/Linux

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/aws-advanced-python-wrapper
Introduced in: 0Fixed in: 1.4.0
Fixpip install --upgrade 'aws-advanced-python-wrapper>=1.4.0'

References