Junglewise Threat Intelligence

CVE-2026-16735: release-it conventional-changelog OS command injection in writeChangelog

CVE-2026-16735 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Executive brief

A security vulnerability exists in the release-it conventional-changelog plugin, which is used to automate the creation of project changelogs. An attacker who can influence the project's configuration can execute unauthorized commands on the system running the software. This could lead to a full system compromise, especially in automated build and deployment environments where sensitive credentials are often stored.

Technical details

An OS command injection vulnerability exists in release-it conventional-changelog up to version 11.0.1. The 'writeChangelog' function in 'index.js' takes the 'infile' argument and interpolates it directly into a shell command (git add ${infile}) without proper sanitization or escaping. A local attacker with the ability to modify the plugin's configuration or command-line arguments can inject shell metacharacters (e.g., semicolons or backticks) to execute arbitrary commands with the privileges of the process. While the attack requires local access to configuration, the impact is high in CI/CD environments. As of the advisory date, the project has been notified but a formal patch has not been confirmed.

Affected products

  • release-it conventional-changelog up to 11.0.1

Timeline

  • 2026-06-17: disclosed: Issue reported to the project maintainers via GitHub issue #149
  • 2026-07-23: advisory: CVE-2026-16735 published by NVD/VulDB

References