{"id":"GHSA-w7h5-55jg-cq2f","summary":"Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde","details":"### Impact\nThis is a **remote code execution (RCE) vulnerability**. Node.js automatically imports `**/*.plugin.{js,mjs}` files including those from `node_modules`, so any malicious package with a `.plugin.js` file could execute arbitrary code when installed or required. **All projects using this loading behavior are affected**, especially those installing untrusted packages.\n\n### Patches\nThe issue has been **patched in v0.0.5**. Users should upgrade to **v0.0.5 or later** to mitigate the vulnerability.\n\n### Workarounds\n- Audit and restrict which packages are installed in `node_modules`.\n\n### References\n- [CWE-94: Improper Control of Generation of Code](https://cwe.mitre.org/data/definitions/94.html)  \n- GitHub Security Advisories documentation: [https://docs.github.com/en/code-security/security-advisories](https://docs.github.com/en/code-security/security-advisories)","aliases":["CVE-2026-26974"],"modified":"2026-02-20T17:03:01.473496Z","published":"2026-02-18T21:45:06Z","database_specific":{"github_reviewed_at":"2026-02-18T21:45:06Z","nvd_published_at":"2026-02-20T01:16:00Z","cwe_ids":["CWE-829"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Tygo-van-den-Hurk/Slyde/security/advisories/GHSA-w7h5-55jg-cq2f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26974"},{"type":"WEB","url":"https://github.com/Tygo-van-den-Hurk/Slyde/commit/e4c215b061e44fd2ead805de34d72642a710af60"},{"type":"PACKAGE","url":"https://github.com/Tygo-van-den-Hurk/Slyde"},{"type":"WEB","url":"https://github.com/Tygo-van-den-Hurk/Slyde/releases/tag/v0.0.5"}],"affected":[{"package":{"name":"@tygo-van-den-hurk/slyde","ecosystem":"npm","purl":"pkg:npm/%40tygo-van-den-hurk/slyde"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-w7h5-55jg-cq2f/GHSA-w7h5-55jg-cq2f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}