{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acyclonedxcyclonedx_cyclonedx_npm/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cyclonedx:cyclonedx_cyclonedx_npm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-71538"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@cyclonedx/cyclonedx-npm (\u003c 6.0.0)"],"_cs_severities":["high"],"_cs_tags":["command-injection","supply-chain","windows"],"_cs_type":"advisory","_cs_vendors":["CycloneDX"],"content_html":"\u003cp\u003eThe npm package \u003ccode\u003e@cyclonedx/cyclonedx-npm\u003c/code\u003e is vulnerable to command injection on Windows systems. The vulnerability resides in how the CLI tool handles the \u003ccode\u003e--workspace\u003c/code\u003e argument. In the tool's fallback execution path, user-supplied input provided to the \u003ccode\u003e--workspace\u003c/code\u003e flag is passed directly to the system shell without sufficient sanitization or neutralization of shell metacharacters.\u003c/p\u003e\n\u003cp\u003eAn attacker who can control or influence the value passed to the \u003ccode\u003e--workspace\u003c/code\u003e flag can inject shell metacharacters such as \u003ccode\u003e\u0026amp;\u003c/code\u003e, \u003ccode\u003e|\u003c/code\u003e, or \u003ccode\u003e\u0026gt;\u003c/code\u003e to break out of the intended command context. This allows for the execution of arbitrary OS commands with the privileges of the user running the CLI tool. This vulnerability was addressed in version 6.0.0 by moving away from the vulnerable fallback path and ensuring input is handled safely.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary command execution on the host machine. This can result in data exfiltration, unauthorized modification of files, or elevation of local privileges depending on the user's current environment. The impact is limited to Windows systems where the vulnerable fallback path is reachable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@cyclonedx/cyclonedx-npm\u003c/code\u003e package to version 6.0.0 or later to apply the fix for CVE-2026-71538.\u003c/li\u003e\n\u003cli\u003eAudit build pipelines and development workflows that invoke this tool to ensure that user-supplied input is not being passed to the \u003ccode\u003e--workspace\u003c/code\u003e argument.\u003c/li\u003e\n\u003cli\u003eOn Windows, if upgrading is not immediately feasible, restrict the use of the tool to trusted inputs only and consider setting the \u003ccode\u003enpm_execpath\u003c/code\u003e environment variable to point to a known safe \u003ccode\u003enpm-cli.js\u003c/code\u003e to potentially bypass the vulnerable fallback path.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T19:15:00Z","date_published":"2026-09-17T19:15:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cyclonedx-npm-injection/","summary":"A command injection vulnerability in @cyclonedx/cyclonedx-npm on Windows allows attackers to execute arbitrary commands by supplying malicious input to the --workspace argument.","title":"Command Injection in @cyclonedx/cyclonedx-npm via --workspace Argument","url":"https://feed.craftedsignal.io/briefs/2026-09-cyclonedx-npm-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cyclonedx:cyclonedx_cyclonedx_npm:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}