What is CVE-2026-16733?
A vulnerability in bahmutov find-cypress-specs up to version 1.54.12 has been identified. The shell.exec function in the src/index.js file's Branch Handler component allows OS command injection via the --branch argument, but the attack is restricted to local execution.
Azərbaycanca: bahmutov find-cypress-specs alətində 1.54.12 versiyasına qədər olan boşluq aşkarlanıb. src/index.js faylındakı Branch Handler komponentinin shell.exec funksiyası, --branch arqumenti vasitəsilə OS command injection zəifliyinə məruz qalır, lakin hücum yalnız lokal icra ilə məhdudlaşır.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What vulnerability was discovered in find-cypress-specs?
A vulnerability in bahmutov find-cypress-specs up to version 1.54.12 allows OS command injection via the --branch argument through the shell.exec function in the src/index.js file's Branch Handler component.
Does the attack require remote or local execution?
The attack is restricted to local execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.