


Perceptive Security
SOC/SIEM Consultancy

@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string conca…
Published:
5 August 2026 at 00:00:00
Alert date:
5 August 2026 at 16:10:56
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
@oblique/cli version 15.4.0 contains an OS command injection vulnerability in its project creation functionality. The CLI tool constructs shell commands via string concatenation and executes them using Node.js execSync(). A user-supplied project-name argument is passed into these shell commands without proper sanitization or neutralization. This allows an attacker to inject shell metacharacters into the project name, causing additional arbitrary operating system commands to be executed. The vulnerability is triggered when the CLI is invoked with a specially crafted project name. This type of injection flaw can lead to full system compromise depending on the privileges of the user running the CLI. It is classified as a high-severity issue given the potential for arbitrary command execution on the host system.
Technical details
Mitigation steps:
Affected products:
@oblique/cli 15.4.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-16022
https://github.com/oblique-bit/oblique/blob/master/projects/cli/CHANGELOG.md
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
