child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-16631. Attacking locally is a requirement. Furthermore, an exploit is available.
It is advisable to implement a patch to correct this issue.
The project maintainer explains: "I think it's very rare for someone to use this package with untrusted input".
Intelligence View
SOCIAL SHARE CARD GENERATOR