Executive brief
Slyde is a Node.js library that automatically loads plugin files from the file system. A critical flaw allows any npm package installed as a dependency to execute arbitrary code simply by including a specially named plugin file, enabling remote code execution when a project installs or uses the library alongside untrusted packages. This could allow attackers to compromise applications, steal sensitive data, or take control of systems running affected code.
Technical details
The vulnerability is a code injection flaw (CWE-829: Inclusion of Functionality from Untrusted Control Sphere) in how Slyde automatically imports **/*.plugin.{js,mjs} files from the Node.js module search path, including those in node_modules. An attacker can craft a malicious npm package containing a .plugin.js file that will be executed automatically when Slyde is loaded or required, without requiring any special configuration or user interaction. This enables remote code execution with the privileges of the Node.js process. The vulnerability affects all versions prior to v0.0.5; a patch is available and users should upgrade immediately.
Affected products
- Tygo-van-den-Hurk Slyde < 0.0.5
Timeline
- 2026-02-18: disclosed: GHSA-w7h5-55jg-cq2f published
- 2026-02-18: patched: Patched in v0.0.5
- 2026-02-20: advisory: NVD published CVE-2026-26974