PT-2026-63510 · Npm · Oclif

·

CVE-2026-16628

·

Published

2026-07-22

·

Updated

2026-07-23

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions oclif versions prior to 4.23.17
Description An OS command injection issue exists in the JIT Plugin Entry Handler component. A local attacker can manipulate the jitPlugins argument to execute arbitrary commands via the child process.exec() function.
Recommendations Deploy patch 939b045725e065baebc4587b8bccfd56731eed3d for versions prior to 4.23.17.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16628

Affected Products

Oclif