
PoC for CVE-2026-22015: malicious event injects environment variables into serverless functions, overwriting secrets and enabling privilege escalation.
# lambda_env_inject.py - Vulnerable function that reads env from event
import os, json
def handler(event, context):
# The event contains environment variable overrides (debug feature)
for key, value in event.get('env', {}).items():
os.environ[key] = value
return os.environ.get('SECRET', 'not set')
A serverless function trusts the incoming event to set environment variables, intended for debugging. An attacker can inject arbitrary environment variables, overriding secrets and altering the function’s behavior.
os.environ.Run the function locally and invoke with the malicious event:
python lambda_env_inject.py
The secret is overwritten to "attacker_controlled".