What is CVE-2026-16735?
CVE-2026-16735 is an OS command injection vulnerability in the `writeChangelog` function of release-it conventional-changelog up to version 11.0.1, triggered by manipulating the `infile` argument. This can allow remote command execution, so users should update immediately and sanitize file path inputs.
Azərbaycanca: CVE-2026-16735, release-it conventional-changelog-un 11.0.1-ə qədər olan versiyalarında `writeChangelog` funksiyasında aşkarlanan OS command injection zəifliyidir. Bu zəiflik `infile` arqumentinin manipulyasiyası ilə uzaqdan əmr icrasına səbəb ola bilər. İstifadəçilər dərhal ən son versiyaya yenilənməli və daxil olan fayl yollarını təmizləməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
How to protect against CVE-2026-16735 vulnerability?
Users should immediately update release-it conventional-changelog to the latest version and sanitize incoming file paths such as `infile`.
What is the cause of CVE-2026-16735 vulnerability?
The vulnerability is an OS command injection in the `writeChangelog` function caused by manipulation of the `infile` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.