CVE-2026-15033

MEDIUM

christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection

Title source: cna
STIX 2.1

Description

A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the file dist/packageUtils.js of the component peerDependencies. This manipulation causes os command injection. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-376784 | christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection
https://vuldb.com/vuln/376784
Signature, Permissions Required signature permissions-required
VDB-376784 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/376784/cti
Third Party Advisory third-party-advisory
CVE-2026-15033 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15033
Third Party Advisory third-party-advisory
Submit #850875 | Node.js check-peer-dependencies 4.3.4 OS Command Injection
https://vuldb.com/submit/850875

Scores

CVSS v3 6.3
EPSS 0.0107
EPSS Percentile 61.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (5)
christopherthielen/check-peer-dependencies 4.3.0
christopherthielen/check-peer-dependencies 4.3.1
christopherthielen/check-peer-dependencies 4.3.2
christopherthielen/check-peer-dependencies 4.3.3
christopherthielen/check-peer-dependencies 4.3.4
Published Jul 08, 2026
Tracked Since Jul 08, 2026