Security Advisory

CVE-2026-16489

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-21 23:30:09
Last updated 2026-07-23 13:54:26
Assigner VulDB
CVSS score 4.8
State PUBLISHED

Description

A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.