Improper Neutralization Vulnerability in Black Duck Package Manager Component
CVE-2026-76055
7.5HIGH
What is CVE-2026-76055?
The vulnerability in the Black Duck package manager component occurs due to improper neutralization of special elements in filesystem paths. When an actor is able to create a file in the scanned build directory, they can potentially execute arbitrary operating system commands via shell metacharacters. The lack of quoting or escaping allows these characters in the filesystem paths to be treated as commands rather than literal text. Consequently, this flaw poses significant security risks as it permits unauthorized command execution without requiring control over the build command or configuration settings.
Affected Version(s)
blackduck-c-cpp 0 < 3.0.7
