OS Command Injection Vulnerability in Danger-js CLI by Danger
CVE-2026-16629
4.8MEDIUM
What is CVE-2026-16629?
An OS command injection vulnerability was found in the danger-js CLI component, specifically in the function danger.git.diffForFile located in source/platforms/git/localGetFileAtSHA.ts. The flaw allows attackers to manipulate function arguments leading to potential system command execution. This vulnerability requires local exploitation, making it crucial for users to upgrade to version 13.0.8, which includes a patch identified by commit 087a7290264cc6fb7154ea8c2552a7b2cb8b33a3 to resolve the issue effectively.
Affected Version(s)
danger-js 13.0.0
danger-js 13.0.1
danger-js 13.0.2
