top of page
perceptive_background_267k.jpg

@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string conca…

Published:

5 augustus 2026 om 00:00:00

Alert date:

5 augustus 2026 om 16:10:56

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

@oblique/cli version 15.4.0 contains an OS command injection vulnerability in its project creation functionality. The CLI tool constructs shell commands via string concatenation and executes them using Node.js execSync(). A user-supplied project-name argument is passed into these shell commands without proper sanitization or neutralization. This allows an attacker to inject shell metacharacters into the project name, causing additional arbitrary operating system commands to be executed. The vulnerability is triggered when the CLI is invoked with a specially crafted project name. This type of injection flaw can lead to full system compromise depending on the privileges of the user running the CLI. It is classified as a high-severity issue given the potential for arbitrary command execution on the host system.

Technical details

Mitigation steps:

Affected products:

@oblique/cli 15.4.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page