OS Command Injection Vulnerability in oclif by Heroku
CVE-2026-16628

4.8MEDIUM

Key Information:

Vendor

Heroku

Status
Vendor
CVE Published:
22 July 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-16628?

A security vulnerability exists in oclif versions up to 4.23.16, allowing local users to exploit the 'child_process.exec' functionality in the JIT Plugin Entry Handler. By manipulating the 'jitPlugins' argument, an attacker can execute arbitrary operating system commands, potentially leading to unauthorized actions on the system. The vulnerability requires local access to exploit and has been made public. Users are advised to apply the available patch (identified by commit 939b045725e065baebc4587b8bccfd56731eed3d) to mitigate this issue.

Affected Version(s)

oclif 4.23.0

oclif 4.23.1

oclif 4.23.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

wjm2 (VulDB User)
.