OS Command Injection Vulnerability in Danger-js CLI by Danger
CVE-2026-16629

4.8MEDIUM

Key Information:

Vendor

Danger

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-16629?

An OS command injection vulnerability was found in the danger-js CLI component, specifically in the function danger.git.diffForFile located in source/platforms/git/localGetFileAtSHA.ts. The flaw allows attackers to manipulate function arguments leading to potential system command execution. This vulnerability requires local exploitation, making it crucial for users to upgrade to version 13.0.8, which includes a patch identified by commit 087a7290264cc6fb7154ea8c2552a7b2cb8b33a3 to resolve the issue effectively.

Affected Version(s)

danger-js 13.0.0

danger-js 13.0.1

danger-js 13.0.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wjm2 (VulDB User)
.