SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16489

MEDIUM · CVSS 5.3 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A command injection vulnerability exists in the jsforce library, specifically in the _execCommand function of the SFDX Connection Registry component, affecting versions up to 3.10.16. This flaw allows an attacker to execute arbitrary operating system commands from a local environment, posing a risk to systems utilizing this library. Organizations using jsforce in their applications should prioritize patching or mitigating this vulnerability to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16489
Severity
MEDIUM
CVSS
5.3
EPSS
0.62%

Original NVD Description

A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.