OS Command Injection Vulnerability in oclif by Heroku
CVE-2026-16628
Key Information:
Badges
What is CVE-2026-16628?
A security vulnerability exists in oclif versions up to 4.23.16, allowing local users to exploit the 'child_process.exec' functionality in the JIT Plugin Entry Handler. By manipulating the 'jitPlugins' argument, an attacker can execute arbitrary operating system commands, potentially leading to unauthorized actions on the system. The vulnerability requires local access to exploit and has been made public. Users are advised to apply the available patch (identified by commit 939b045725e065baebc4587b8bccfd56731eed3d) to mitigate this issue.
Affected Version(s)
oclif 4.23.0
oclif 4.23.1
oclif 4.23.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
