关键信息 CVE ID: CVE-2025-12815 Bulletin ID: AWS-2025-026 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/11/6 9:15 AM PDT Description Research and Engineering Studio on AWS (RES) is an open-source web-based portal. A vulnerability in the Virtual Desktop preview page allows an authenticated remote user to view another user's active desktop session metadata, including periodic desktop preview screenshots. Impacted Versions < 2025.09 Resolution Addressed in RES version 2025.09. Recommend upgrading to the latest version and ensuring any forked or derivative code is patched. References CVE-2025-12815 GHSA-x3cx-q8g9-75hv Contact Security questions: aws-security@amazon.com