What is CVE-2026-16489?
A vulnerability found in jsforce up to version 3.10.16, affecting the _execCommand function within the SFDX Connection Registry component. It allows OS command injection, exploitable only from a local environment. Updating jsforce is recommended to mitigate this issue.
Azərbaycanca: Bu boşluq jsforce kitabxanasının 3.10.16 versiyasına qədər olan versiyalarda aşkarlanıb. SFDX Connection Registry komponentindəki _execCommand funksiyası vasitəsilə lokal mühitdən OS command injection həyata keçirmək mümkündür. Bu problemi aradan qaldırmaq üçün jsforce kitabxanasını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which versions of the jsforce library are affected by CVE-2026-16489?
The CVE-2026-16489 vulnerability affects jsforce library versions up to 3.10.16.
Under what condition can CVE-2026-16489 be exploited?
This vulnerability can only be exploited from a local environment.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.