Malicious Code in Bitwarden CLI from Checkmarx Supply Chain Incident
CVE-2026-42994

8.8HIGH

Key Information:

Vendor

Bitwarden

Vendor
CVE Published:
1 May 2026

What is CVE-2026-42994?

Bitwarden CLI version 2026.4.0, distributed via npm, contained embedded malicious code due to a supply chain breach associated with Checkmarx. This incident highlights the vulnerability of software supply chains and the risks involved with using third-party code without adequate safeguards. Users are advised to ensure they are using secure versions and regularly monitor their software for unrecognized changes.

Affected Version(s)

Bitwarden CLI 2026.4.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.