Impact
The vulnerability arises in the @cyclonedx/cyclonedx-npm package when the Windows fallback path uses unsanitized input from the --workspace option to build a shell command. An attacker who can influence that option may inject shell metacharacters, enabling execution of arbitrary operating‑system commands with the privileges of the user running the CLI. This can lead to data exposure, file alteration, or service disruption. The weakness is a classic command injection (CWE‑78).
Affected Systems
CycloneDX, cyclonedx-node‑npm, affected by all releases prior to v6.0.0 on Windows when the npm_execpath does not provide a CI/CD path and the fallback path is used. The issue is fixed in version 6.0.0.
Risk and Exploitability
With a CVSS score of 8.5 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate exploitation probability. The likely attack vector involves supplying a malicious --workspace value when the fallback path is triggered, which requires the attacker to inject commands via a command line argument. If successfully exploited, the attacker would gain the same privileges as the node process and could execute arbitrary OS commands.
OpenCVE Enrichment
Github GHSA