PT-2026-63512 · Syncfusion · Ej2-Javascript-Ui-Controls

·

CVE-2026-16630

·

Published

2026-07-22

·

Updated

2026-07-23

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions syncfusion ej2-javascript-ui-controls versions prior to 33.2.4
Description An OS command injection flaw exists when the software is accessed locally. The issue resides in the child process.exec() function within the package.json file, where improper manipulation allows the execution of arbitrary operating system commands.
Recommendations Update syncfusion ej2-javascript-ui-controls to version 33.2.4 or later.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16630

Affected Products

Ej2-Javascript-Ui-Controls