Description
@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpath does not provide the npm CLI path, can construct a shell command containing an untrusted value from the --workspace option. When an attacker can influence that option and the fallback npm execution path is reached, shell metacharacters in the workspace value can execute arbitrary operating-system commands with the privileges of the user running the CLI, allowing data access, file modification, or service disruption. This issue is fixed in version 6.0.0.
Published: 2026-09-17
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via shell injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises in the @cyclonedx/cyclonedx-npm package when the Windows fallback path uses unsanitized input from the --workspace option to build a shell command. An attacker who can influence that option may inject shell metacharacters, enabling execution of arbitrary operating‑system commands with the privileges of the user running the CLI. This can lead to data exposure, file alteration, or service disruption. The weakness is a classic command injection (CWE‑78).

Affected Systems

CycloneDX, cyclonedx-node‑npm, affected by all releases prior to v6.0.0 on Windows when the npm_execpath does not provide a CI/CD path and the fallback path is used. The issue is fixed in version 6.0.0.

Risk and Exploitability

With a CVSS score of 8.5 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate exploitation probability. The likely attack vector involves supplying a malicious --workspace value when the fallback path is triggered, which requires the attacker to inject commands via a command line argument. If successfully exploited, the attacker would gain the same privileges as the node process and could execute arbitrary OS commands.

Generated by OpenCVE AI on September 17, 2026 at 20:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade cyclonedx-node-npm to v6.0.0 or later, which sanitizes the --workspace argument.
  • Ensure the NPM executable path is explicitly set (e.g., via npm_execpath or environment variables) so the fallback path is not used on Windows.
  • If an upgrade is not immediately possible, restrict or validate any user‑supplied --workspace values to a whitelist of known safe paths and avoid executing the tool in a context where shell injection could be triggered.

Generated by OpenCVE AI on September 17, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q69g-4hcv-6jg4 @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
History

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Cyclonedx
Cyclonedx cyclonedx Node Npm
Vendors & Products Cyclonedx
Cyclonedx cyclonedx Node Npm

Thu, 17 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpath does not provide the npm CLI path, can construct a shell command containing an untrusted value from the --workspace option. When an attacker can influence that option and the fallback npm execution path is reached, shell metacharacters in the workspace value can execute arbitrary operating-system commands with the privileges of the user running the CLI, allowing data access, file modification, or service disruption. This issue is fixed in version 6.0.0.
Title @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cyclonedx Cyclonedx Node Npm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:30:52.840Z

Reserved: 2026-08-06T21:24:15.375Z

Link: CVE-2026-71538

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T15:16:51.100

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-71538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:12Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')