OS Command Injection in Better-NPM-Audit by Jeemok
CVE-2026-57998

8.5HIGH

Key Information:

Vendor

Jeemok

Vendor
CVE Published:
22 August 2026

What is CVE-2026-57998?

A vulnerability exists in Better-NPM-Audit where user-supplied --registry options are not properly validated, allowing an attacker to inject shell metacharacters into the command string. This can lead to arbitrary command execution with the privileges of the process, posing significant security risks.

Affected Version(s)

better-npm-audit 0 <= 3.11.0

better-npm-audit 4.0.0-rc.2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MD Mahmidul Hasan (BL4CK 570RM)
.