_execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-16489. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
Intelligence View
SOCIAL SHARE CARD GENERATOR