CVE-2026-16733
bahmutov find-cypress-specs Branch index.js shell.exec os command injection
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
| CWE | CWE-78 CWE-77 |
| Vendor | bahmutov |
| Product | find-cypress-specs |
| Published | Jul 23, 2026 |
| Last Updated | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for bahmutov find-cypress-specs
Be the first to know when new medium vulnerabilities affecting bahmutov find-cypress-specs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
bahmutov / find-cypress-specs
1.54.0 1.54.1 1.54.2 1.54.3 1.54.4 1.54.5 1.54.6 1.54.7 1.54.8 1.54.9 1.54.10 1.54.11 1.54.12
References
vuldb.com: https://vuldb.com/vuln/382478 vuldb.com: https://vuldb.com/vuln/382478/cti vuldb.com: https://vuldb.com/cve/CVE-2026-16733 vuldb.com: https://vuldb.com/submit/861021 github.com: https://github.com/bahmutov/find-cypress-specs/issues/423 github.com: https://github.com/bahmutov/find-cypress-specs/
Credits
๐ wjm2 (VulDB User) VulDB CNA Team