CVE-2026-16629 PUBLISHED

danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection

Assigner: VulDB
Reserved: 22.07.2026 Published: 22.07.2026 Updated: 22.07.2026

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os command injection. The attack needs to be performed locally. Upgrading to version 13.0.8 is recommended to address this issue. The name of the patch is 087a7290264cc6fb7154ea8c2552a7b2cb8b33a3. It is advisable to upgrade the affected component.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 4.8

Product Status

Vendor danger
Product danger-js
Versions
  • Version 13.0.0 is affected
  • Version 13.0.1 is affected
  • Version 13.0.2 is affected
  • Version 13.0.3 is affected
  • Version 13.0.4 is affected
  • Version 13.0.5 is affected
  • Version 13.0.6 is affected
  • Version 13.0.7 is affected
  • Version 13.0.8 is unaffected

Credits

  • wjm2 (VulDB User) reporter

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE