THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wcx4-wpfv-mc5c (high) — jsii-diff: Command Injection via npm: package argument

[GHSA] GHSA-wcx4-wpfv-mc5c (high) — jsii-diff: Command Injection via npm: package argument

medgithub_advisoriesPublished 2026-08-07

GHSA-wcx4-wpfv-mc5c Severity: high CVE: CVE-2026-15895

jsii-diff: Command Injection via npm: package argument

## Summary

jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via th

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wcx4-wpfv-mc5c