A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16489.json",
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "3.10.12"
},
{
"last_affected": "3.10.12"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-77",
"CWE-78"
]
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "3.10.0"
},
{
"last_affected": "3.10.0"
},
{
"introduced": "3.10.1"
},
{
"last_affected": "3.10.1"
},
{
"introduced": "3.10.2"
},
{
"last_affected": "3.10.2"
},
{
"introduced": "3.10.3"
},
{
"last_affected": "3.10.3"
},
{
"introduced": "3.10.4"
},
{
"last_affected": "3.10.4"
},
{
"introduced": "3.10.5"
},
{
"last_affected": "3.10.5"
},
{
"introduced": "3.10.6"
},
{
"last_affected": "3.10.6"
},
{
"introduced": "3.10.7"
},
{
"last_affected": "3.10.7"
},
{
"introduced": "3.10.8"
},
{
"last_affected": "3.10.8"
},
{
"introduced": "3.10.9"
},
{
"last_affected": "3.10.9"
},
{
"introduced": "3.10.10"
},
{
"last_affected": "3.10.10"
},
{
"introduced": "3.10.11"
},
{
"last_affected": "3.10.11"
},
{
"introduced": "3.10.13"
},
{
"last_affected": "3.10.13"
},
{
"introduced": "3.10.14"
},
{
"last_affected": "3.10.14"
},
{
"introduced": "3.10.15"
},
{
"last_affected": "3.10.15"
},
{
"introduced": "3.10.16"
},
{
"last_affected": "3.10.16"
}
]
}