CVE-2026-16628
oclif JIT Plugin Entry child_process.exec os command injection
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command injection. The attack is only possible with local access. The exploit is now public and may be used. The patch is named 939b045725e065baebc4587b8bccfd56731eed3d. To fix this issue, it is recommended to deploy a patch.
| CWE | CWE-78 CWE-77 |
| Vendor | n/a |
| Product | oclif |
| Published | Jul 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a oclif
Be the first to know when new medium vulnerabilities affecting n/a oclif are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / oclif
4.23.0 4.23.1 4.23.2 4.23.3 4.23.4 4.23.5 4.23.6 4.23.7 4.23.8 4.23.9 4.23.10 4.23.11 4.23.12 4.23.13 4.23.14 4.23.15 4.23.16
References
vuldb.com: https://vuldb.com/vuln/382372 vuldb.com: https://vuldb.com/vuln/382372/cti vuldb.com: https://vuldb.com/cve/CVE-2026-16628 vuldb.com: https://vuldb.com/submit/860149 github.com: https://github.com/oclif/oclif/issues/2051 github.com: https://github.com/oclif/oclif/pull/2052 github.com: https://github.com/oclif/oclif/commit/939b045725e065baebc4587b8bccfd56731eed3d github.com: https://github.com/oclif/oclif/
Credits
๐ wjm2 (VulDB User)