Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 07 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Swiss Federal Office Of Information Technology, Systems And Telecommunication
Swiss Federal Office Of Information Technology, Systems And Telecommunication oblique/cli |
|
| Vendors & Products |
Swiss Federal Office Of Information Technology, Systems And Telecommunication
Swiss Federal Office Of Information Technology, Systems And Telecommunication oblique/cli |
Wed, 05 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command without proper neutralization, allowing shell metacharacters to execute additional operating-system commands when the CLI is invoked with a crafted project name. | |
| Title | Command Injection in @oblique/cli | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-08-05T15:28:35.463Z
Reserved: 2026-07-17T07:06:27.045Z
Link: CVE-2026-16022
Updated: 2026-08-05T15:28:31.613Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T10:07:05Z