Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
Command Injection in @oblique/cli
CVE-2026-16022
Description
@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command without proper neutralization, allowing shell metacharacters to execute additional operating-system commands when the CLI is invoked with a crafted project name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <15.4.0
Patches
Vulnerability mechanics
References
1- github.com/oblique-bit/oblique/blob/master/projects/cli/CHANGELOG.mdmitrerelease-notes
News mentions
0No linked articles in our index yet.