OS Command Injection in Better-NPM-Audit by Jeemok
CVE-2026-57998
8.5HIGH
What is CVE-2026-57998?
A vulnerability exists in Better-NPM-Audit where user-supplied --registry options are not properly validated, allowing an attacker to inject shell metacharacters into the command string. This can lead to arbitrary command execution with the privileges of the process, posing significant security risks.
Affected Version(s)
better-npm-audit 0 <= 3.11.0
better-npm-audit 4.0.0-rc.2
