Medium · 4.7 Node.js & npm GHSA-q69g-4hcv-6jg4 CVE-2026-71538
OS Command Injection in @cyclonedx/cyclonedx-npm via Windows --workspace Fallback (CVE-2026-71538)
A Windows-specific fallback code path in @cyclonedx/cyclonedx-npm versions before 6.0.0 can execute arbitrary OS commands if an attacker controls the --workspace option. The issue is fixed in version 6.0.0.
AI summary
A vulnerability has been identified in @cyclonedx/cyclonedx-npm, a tool used to generate CycloneDX Software Bills of Materials (SBOMs) from npm projects. The flaw, tracked as CVE-2026-71538, affects a Windows-specific fallback mechanism used when the npm CLI path cannot be determined through the normal environment variable. Versions prior to 6.0.0 are affected, and a fix is available in version 6.0.0.
What Happened
A security issue was disclosed in @cyclonedx/cyclonedx-npm affecting the Windows fallback path in the tool's npm runner logic (src/npmRunner.ts). This fallback is used when the npm_execpath environment variable does not provide the path to the npm CLI. In that fallback path, the tool can construct a shell command that includes an untrusted value taken from the --workspace option. If shell metacharacters are present in that value, they can be executed as part of the shell command.
Technical Cause
The vulnerability is classified as CWE-78, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). The root cause is that the value passed to the --workspace option is not sanitized before being incorporated into a shell command string on the Windows fallback execution path. When an attacker can influence the value supplied to --workspace and the fallback path is triggered, shell metacharacters in that value can cause arbitrary operating system commands to run with the privileges of the user invoking the CLI.
Why It Matters
Successful exploitation allows arbitrary command execution with the privileges of the user running the @cyclonedx/cyclonedx-npm CLI. According to the fact package, this could lead to data access, file modification, or service disruption. Because SBOM generation tools are often run as part of build or CI pipelines, a command injection in this context could affect automated environments where the tool is invoked, particularly if any part of the build process allows external input to reach the --workspace option.
Who Is Affected
Users of the @cyclonedx/cyclonedx-npm npm package running on Windows are affected, specifically in scenarios where the npm_execpath environment variable does not provide the npm CLI path and the tool falls back to the alternate execution path described in the advisory. Exploitation requires that an attacker is able to influence the value passed to the --workspace option.
Affected Versions
All versions of @cyclonedx/cyclonedx-npm prior to version 6.0.0 are affected, per the advisory's affected range (introduced at version 0, fixed in version 6.0.0).
Fixes and Mitigation
This issue is fixed in @cyclonedx/cyclonedx-npm version 6.0.0. No mitigations other than upgrading are described in the available fact package.
Recommended Action
Update @cyclonedx/cyclonedx-npm to version 6.0.0 or later. Teams running the tool on Windows, especially within automated build or CI pipelines, should prioritize this update and review whether any untrusted input could reach the --workspace option prior to patching.
PatchBriefing score
4.7 / 10 · Medium
Official CVSS: 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
Patchwire assigned a score of 4.7 based primarily on the CVSS 4.0 base score of 8.5, which reflects high impact on confidentiality, integrity, and availability for a local attack vector requiring low attack complexity and no privileges, though with required user interaction. No known exploitation in the wild, no public exploit code, and no EPSS data were factored in as contributing elements, and a fix is available, which further moderates the overall score relative to the base CVSS rating.
Affected versions
- @cyclonedx/cyclonedx-npm < 6.0.0
- vulnerable
- ≥ 6.0.0
- patched
Reported fixes
This issue is fixed in @cyclonedx/cyclonedx-npm version 6.0.0. No mitigations other than upgrading are described in the available fact package.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email