{"id":"CVE-2021-4326","aliases":["GHSA-6q8m-42qq-64r7"],"url":"https://o3.security/vulnerability/CVE-2021-4326","summary":"Imperative CLI vulnerable to Command Injection","details":"A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.","published":"2023-03-01T08:15:10.187Z","modified":"2026-07-09T06:35:07.112527Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@zowe/imperative","fixedVersion":"5.7.1"},{"ecosystem":"npm","name":"@zowe/imperative","fixedVersion":"4.18.10"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/zowe/imperative/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T06:35:07.112527Z"}}