CVE-2026-16628 | oclif up to 4.23.16 JIT Plugin Entry child_process.exec jitPlugins os command injection (Issue 2051)
A vulnerability has been found in oclif up to 4.23.16 and classified as critical. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command injection.
This vulnerability is identified as CVE-2026-16628. The attack is only possible with local access. Additionally, an exploit exists.
To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More