CVE-2026-16628 | oclif up to 4.23.16 JIT Plugin Entry child_process.exec jitPlugins os command injection (Issue 2051)

SecurityVulns

A vulnerability has been found in oclif up to 4.23.16 and classified as critical. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command injection.

This vulnerability is identified as CVE-2026-16628. The attack is only possible with local access. Additionally, an exploit exists.

To fix this issue, it is recommended to deploy a patch.VulDB Recent EntriesRead More