Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jonas Friedli

#17440of 56,330
16.4Total CVSS
Vulnerabilities · 2
High
2
PT-2026-68127
7.8
2026-08-05
Npm · @Oblique/Cli · CVE-2026-16022
**Name of the Vulnerable Software and Affected Versions** @oblique/cli version 15.4.0 **Description** An OS command injection issue exists in the project creation functionality. The application constructs shell commands using string concatenation and executes them via the `execSync()` function. Because the `project-name` argument is inserted into the command without proper neutralization, an attacker can use shell metacharacters to execute arbitrary operating-system commands when the CLI is invoked with a specially crafted project name. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-50878
8.6
2026-06-19
Sima Gmbh · Bondix · CVE-2026-12104
**Name of the Vulnerable Software and Affected Versions** SIMA GmbH Bondix versions prior to 1.25.7.6 **Description** OS command injection exists in the environment and tunnel configuration functionality on Linux. An authenticated attacker with configuration write access can execute arbitrary operating-system commands by providing crafted configuration values to server-side scripts. **Recommendations** Update to a version newer than 1.25.7.5.