THREAT OPS › Threat News › [GHSA] GHSA-wcx4-wpfv-mc5c (high) — jsii-diff: Command Injection via npm: package argument
[GHSA] GHSA-wcx4-wpfv-mc5c (high) — jsii-diff: Command Injection via npm: package argument
GHSA-wcx4-wpfv-mc5c Severity: high CVE: CVE-2026-15895
jsii-diff: Command Injection via npm: package argument
## Summary
jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via th
Indicators of compromise
- CVE-2026-15895cve
Original source: https://github.com/advisories/GHSA-wcx4-wpfv-mc5c