{"id":"CVE-2026-16489","summary":"jsforce SFDX Connection Registry sfdx.js _execCommand os command injection","details":"A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.","modified":"2026-07-25T03:56:13.771703034Z","published":"2026-07-21T23:30:09.680Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16489.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.10.12"},{"last_affected":"3.10.12"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB","cwe_ids":["CWE-77","CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/jsforce/jsforce/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16489.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16489"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-16489"},{"type":"ADVISORY","url":"https://vuldb.com/submit/860031"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/380946"},{"type":"REPORT","url":"https://github.com/jsforce/jsforce/issues/1805"},{"type":"REPORT","url":"https://vuldb.com/vuln/380946/cti"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jsforce/jsforce","events":[{"introduced":"f9762f0a06314eb20b3a6bfdf575106890f06646"},{"last_affected":"0d8f4804ca281b5c26f691dc9f921633d99dad49"}],"database_specific":{"extracted_events":[{"introduced":"3.10.0"},{"last_affected":"3.10.0"},{"introduced":"3.10.1"},{"last_affected":"3.10.1"},{"introduced":"3.10.2"},{"last_affected":"3.10.2"},{"introduced":"3.10.3"},{"last_affected":"3.10.3"},{"introduced":"3.10.4"},{"last_affected":"3.10.4"},{"introduced":"3.10.5"},{"last_affected":"3.10.5"},{"introduced":"3.10.6"},{"last_affected":"3.10.6"},{"introduced":"3.10.7"},{"last_affected":"3.10.7"},{"introduced":"3.10.8"},{"last_affected":"3.10.8"},{"introduced":"3.10.9"},{"last_affected":"3.10.9"},{"introduced":"3.10.10"},{"last_affected":"3.10.10"},{"introduced":"3.10.11"},{"last_affected":"3.10.11"},{"introduced":"3.10.13"},{"last_affected":"3.10.13"},{"introduced":"3.10.14"},{"last_affected":"3.10.14"},{"introduced":"3.10.15"},{"last_affected":"3.10.15"},{"introduced":"3.10.16"},{"last_affected":"3.10.16"}],"source":"AFFECTED_FIELD"}}],"versions":["3.10.0","3.10.1","3.10.10","3.10.11","3.10.13","3.10.14","3.10.15","3.10.16","3.10.2","3.10.3","3.10.4","3.10.5","3.10.6","3.10.7","3.10.8","3.10.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16489.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}