CVE-2026-16631 | publint up to 0.1.4 package-manager Command src/node/pack.js child_process.exec os command injection (Issue 236)

SecurityVulns

A vulnerability described as problematic has been identified in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection.

This vulnerability is known as CVE-2026-16631. Attacking locally is a requirement. Furthermore, an exploit is available.

It is advisable to implement a patch to correct this issue.

The project maintainer explains: “I think it’s very rare for someone to use this package with untrusted input”.VulDB Recent EntriesRead More