High severity7.8NVD Advisory· Published Aug 5, 2026· Updated Aug 26, 2026
CVE-2026-16022
CVE-2026-16022
Description
@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command without proper neutralization, allowing shell metacharacters to execute additional operating-system commands when the CLI is invoked with a crafted project name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <15.4.0
- Range: <15.4.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.