danger allows local OS command injection through crafted file paths
GHSA-3x93-p86w-5jvh · CVE-2026-16629
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os command injection. The attack needs to be performed locally. Upgrading to version 13.0.8 is recommended to address this issue. The name of the patch is 087a7290264cc6fb7154ea8c2552a7b2cb8b33a3. It is advisable to upgrade the affected component.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-16629
- WEB https://github.com/danger/danger-js/pull/1513
- WEB https://github.com/danger/danger-js/commit/087a7290264cc6fb7154ea8c2552a7b2cb8b33a3
- PACKAGE https://github.com/danger/danger-js
- WEB https://github.com/danger/danger-js/releases/tag/13.0.8
- WEB https://vuldb.com/cve/CVE-2026-16629
- WEB https://vuldb.com/submit/860211
- WEB https://vuldb.com/vuln/382377
- WEB https://vuldb.com/vuln/382377/cti
Ready to move
Start Securing
Free, no credit card | First findings in minutes