High severityNVD Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-55849
CVE-2026-55849
Description
@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking user. This issue is fixed in version 5.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@cyclonedx/cyclonedx-npmnpm | >= 2.1.0, < 5.0.0 | 5.0.0 |
Affected products
1- Range: >=2.1.0 <5.0.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-v75r-vx73-82pjghsaADVISORY
- github.com/CycloneDX/cyclonedx-node-npm/pull/1476nvdWEB
- github.com/CycloneDX/cyclonedx-node-npm/releases/tag/v5.0.0nvdWEB
- github.com/CycloneDX/cyclonedx-node-npm/security/advisories/GHSA-v75r-vx73-82pjnvdWEB
- github.com/CycloneDX/cyclonedx-node-npm/commit/9f646253f4263d8644dadb86e5597fad996f688fnvd
News mentions
0No linked articles in our index yet.