What is CVE-2026-16631?
This CVE describes an OS command injection vulnerability in 'publint' up to version 0.1.4, specifically through the 'child_process.exec' function in 'src/node/pack.js'. Successful exploitation requires local access, allowing an attacker to execute arbitrary commands. Users should update the affected package immediately to mitigate the risk.
Azərbaycanca: Bu CVE, 0.1.4 versiyasına qədər olan 'publint' paketində aşkar edilmiş OS command injection zəifliyini əhatə edir. Zəiflik, xüsusilə 'src/node/pack.js' faylındakı 'child_process.exec' funksiyası vasitəsilə baş verir və yerli şəbəkədə hücum edən şəxsə əmrlər icra etməyə imkan verir. Təsirlənmiş versiyaları dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which versions of the 'publint' package are affected by CVE-2026-16631?
This vulnerability affects 'publint' package versions up to and including 0.1.4.
What type of access is required for an attacker to successfully exploit CVE-2026-16631?
Required attacker access is local access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.