HIGH 7.8 GitHub

CVE-2026-15895

jsii-diff: Command Injection via npm: package argument

## Summary jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via this tool. ## Impact jsii-diff supports downloading packages to compare directly from NPM, so that you can compare a proposed candidate version of your jsii package with an already-published version, by passing an

Affected Products

References

Published: 2026-08-07 · Source: GitHub · Feed updated: 2026-08-10
This high severity vulnerability with a CVSS score of 7.8 was published on 2026-08-07 via GitHub. Affected: npm/jsii-diff < 1.131.0.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.