@cyclonedx/cdxgen Maven Scanner Command Injection

Confirmed
Discovered Jun 26, 2026

CycloneDX cdxgen before 12.4.3 could execute shell metacharacters from repository-controlled Maven module paths when scanning attacker-controlled projects, putting developer workstations and CI SBOM runners at risk.

1
Affected Packages
10
Observables
4
Sources

Timeline

1 of 1 rows

Timeline
DateEventDescriptionSource
Jun 26, 2026Fresh source reviewReviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data.Direct source

Affected Software

1 of 1 rows

Affected Software
PackageEcosystemVersion RangeStatusConfidenceSource
@cyclonedx/cdxgen < 12.4.3npmunknownMalicious90%Direct source

IOC Clipboard

10 IOCs
urlhttps://github.com/cdxgen/cdxgen/security/advisories/GHSA-5vwr-qchf-q4pf
urlhttps://github.com/cdxgen/cdxgen/pull/4059
file_pathpackage.json
file_pathpackage-lock.json
file_pathpnpm-lock.yaml
file_pathyarn.lock
file_path.github/workflows
commandcdxgen
command--type maven
command-t maven

Provenance & Sources

4 of 4 rows

Provenance & Sources
SourceTypeReliabilityClaimsEvidence
Direct sourcedirect95%1https://github.com/cdxgen/cdxgen/security/advisories/GHSA-5vwr-qchf-q4pf
Direct sourcedirect95%1https://github.com/cdxgen/cdxgen/pull/4059
Primary researchprimary research95%1https://github.com/cdxgen/cdxgen/security/advisories/GHSA-5vwr-qchf-q4pf
Correlated sourcecorrelated80%1https://github.com/advisories/GHSA-5vwr-qchf-q4pf