THREAT OPS › Threat News › [GHSA] GHSA-q69g-4hcv-6jg4 (high) — @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
[GHSA] GHSA-q69g-4hcv-6jg4 (high) — @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
GHSA-q69g-4hcv-6jg4 Severity: high CVE: CVE-2026-71538
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows
## Summary
A **Windows-specific** command injection vulnerability exists in `@cyclonedx/cyclonedx-npm` when the CLI is invoked with the `--workspace <value>` option. User-supplied `--workspace` values can be passed to a shell command without proper n
Indicators of compromise
- CVE-2026-71538cve
Original source: https://github.com/advisories/GHSA-q69g-4hcv-6jg4