CVE-2026-16630
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and may be used.
| CWE | CWE-78 CWE-77 |
| Vendor | syncfusion |
| Product | ej2-javascript-ui-controls |
| Published | Jul 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for syncfusion ej2-javascript-ui-controls
Be the first to know when new medium vulnerabilities affecting syncfusion ej2-javascript-ui-controls are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
syncfusion / ej2-javascript-ui-controls
33.2.0 33.2.1 33.2.2 33.2.3
References
vuldb.com: https://vuldb.com/vuln/382380 vuldb.com: https://vuldb.com/vuln/382380/cti vuldb.com: https://vuldb.com/cve/CVE-2026-16630 vuldb.com: https://vuldb.com/submit/860232 github.com: https://github.com/syncfusion/ej2-javascript-ui-controls/issues/215 github.com: https://github.com/syncfusion/ej2-javascript-ui-controls/
Credits
๐ wjm2 (VulDB User)