A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection. Attacking locally is a requirement. The exploit is now public and may be used. The patch is identified as adf2d9a09945fc98c85a2520a89f441d78b2dbd8. It is advisable to implement a patch to correct this issue. The project maintainer explains: "I think it's very rare for someone to use this package with untrusted input".
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection. Attacking locally is a requirement. The exploit is now public and may be used. The patch is identified as adf2d9a09945fc98c85a2520a89f441d78b2dbd8. It is advisable to implement a patch to correct this issue. The project maintainer explains: "I think it's very rare for someone to use this package with untrusted input". | |
| Title | publint package-manager pack.js child_process.exec os command injection | |
| First Time appeared |
Publint
Publint publint |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:publint:publint:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Publint
Publint publint |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-07-22T23:30:14.981Z
Updated: 2026-07-22T23:30:14.981Z
Reserved: 2026-07-22T16:08:22.735Z
Link: CVE-2026-16631
No data.
No data.
No data.