What is CVE-2026-16628?
An OS command injection vulnerability was found in oclif up to version 4.23.16, affecting the child_process.exec function within the JIT Plugin Entry Handler. By manipulating the jitPlugins argument, an attacker with local access can execute arbitrary commands. Users should update to the latest version and avoid untrusted plugins.
Azərbaycanca: oclif alətinin 4.23.16 versiyasına qədər olan versiyalarında JIT Plugin Entry Handler komponentindəki child_process.exec funksiyası vasitəsilə OS command injection zəifliyi aşkar edilib. Bu zəiflik jitPlugins arqumentinin manipulyasiyası ilə yerli giriş tələb edərək ixtiyari əmrlərin icrasına imkan verir. İstifadəçilərə ən son versiyaya yeniləmə və etibarsız plugin-lərdən çəkinmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which versions of oclif are affected by CVE-2026-16628?
Versions of oclif up to 4.23.16 are affected by this vulnerability.
Is local access required to exploit CVE-2026-16628?
Yes, local access is required to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.