OS Command Injection Vulnerability in jsforce Library by jsforce
CVE-2026-16489
Key Information:
Badges
What is CVE-2026-16489?
A vulnerability has been discovered in the jsforce library, specifically in the function _execCommand located in lib/registry/sfdx.js. This flaw allows for os command injection, posing a risk to local environments where the code is executed. Exploitation of this vulnerability can lead to unauthorized command execution on the host system. The issue has been acknowledged by the project maintainers following a report, but no remediation has been provided as of yet. Users of jsforce up to version 3.10.16 should be aware of this vulnerability and take necessary precautions to mitigate potential risks.
Affected Version(s)
jsforce 3.10.0
jsforce 3.10.1
jsforce 3.10.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
