{"id":"CVE-2026-55849","aliases":["GHSA-v75r-vx73-82pj"],"url":"https://o3.security/vulnerability/CVE-2026-55849","summary":"@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument","details":"@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking user. This issue is fixed in version 5.0.0.","published":"2026-07-08T21:10:15.798Z","modified":"2026-08-12T03:51:26.785430783Z","cvss":null,"epss":{"score":0.00161,"percentile":0.05792,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@cyclonedx/cyclonedx-npm","fixedVersion":"5.0.0"}],"fix":{"url":"https://github.com/CycloneDX/cyclonedx-node-npm/commit/9f646253f4263d8644dadb86e5597fad996f688f","label":"CycloneDX/cyclonedx-node-npm@9f64625"},"references":[{"type":"WEB","url":"https://github.com/CycloneDX/cyclonedx-node-npm/releases/tag/v5.0.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55849.json"},{"type":"ADVISORY","url":"https://github.com/CycloneDX/cyclonedx-node-npm/security/advisories/GHSA-v75r-vx73-82pj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55849"},{"type":"FIX","url":"https://github.com/CycloneDX/cyclonedx-node-npm/commit/9f646253f4263d8644dadb86e5597fad996f688f"},{"type":"FIX","url":"https://github.com/CycloneDX/cyclonedx-node-npm/pull/1476"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.785430783Z"}}