THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q69g-4hcv-6jg4 (high) — @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows

[GHSA] GHSA-q69g-4hcv-6jg4 (high) — @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows

medgithub_advisoriesPublished 2026-09-17

GHSA-q69g-4hcv-6jg4 Severity: high CVE: CVE-2026-71538

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows

## Summary

A **Windows-specific** command injection vulnerability exists in `@cyclonedx/cyclonedx-npm` when the CLI is invoked with the `--workspace <value>` option. User-supplied `--workspace` values can be passed to a shell command without proper n

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q69g-4hcv-6jg4