CVE-2026-16489 | jsforce up to 3.10.16 SFDX Connection Registry lib/registry/sfdx.js _execCommand os command injection (Issue 1805)
A vulnerability was found in jsforce up to 3.10.16. It has been classified as critical. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-16489. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More