CVE-2026-16735
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of th
CVSS
5.3
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-77 · CWE-78
Sin historial EPSS suficiente todavía.
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
- github.comhttps://github.com/release-it/conventional-changelog/
- github.comhttps://github.com/release-it/conventional-changelog/issues/149
- vuldb.comhttps://vuldb.com/cve/CVE-2026-16735
- vuldb.comhttps://vuldb.com/submit/861024
- vuldb.comhttps://vuldb.com/vuln/382479
- vuldb.comhttps://vuldb.com/vuln/382479/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-651610.0 CRÍ—
———Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.3hCVE-2026-167335.3 MED—
———A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.5hCVE-2026-162877.8 ALT54.1%
——16Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection.
This issue affects pardus-update: from 0.6.6 before 0.7.0.7hCVE-2026-166315.3 MED61.7%
——19A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection. Attacking locally is a requirement. The exploit is now public and may be used. The patch is identified as adf2d9a09945fc98c85a2520a89f441d78b2dbd8. It is advisable to implement a patch to correct this issue. The project maintainer explains: "I think it's very rare for someone to use this package with untrusted input".6hCVE-2026-166305.3 MED61.7%
——19A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and may be used.6hCVE-2026-166295.3 MED61.7%
——19A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os command injection. The attack needs to be performed locally. Upgrading to version 13.0.8 is recommended to address this issue. The name of the patch is 087a7290264cc6fb7154ea8c2552a7b2cb8b33a3. It is advisable to upgrade the affected component.6h