Junglewise Threat Intelligence

CVE-2026-57998: better-npm-audit command injection in --registry option

CVE-2026-57998 · Severity: high · CVSS 7.8 · Published 2026-08-22

Executive brief

better-npm-audit is a Node.js tool that enhances npm's built-in security scanning capabilities. The tool builds npm audit commands by directly inserting user-supplied registry URLs without proper sanitization, then executes them through a system shell. An attacker can inject shell metacharacters into the registry URL to execute arbitrary operating system commands with the privileges of the process running the audit.

Technical details

This is a command injection vulnerability in the --registry option handler. The vulnerable code in src/handlers/handleInput.ts interpolates the user-supplied --registry parameter directly into a command string without validation or shell escaping. This unsanitized string is then passed to child_process.exec() in index.ts, which spawns a shell to execute the command. An attacker can inject shell metacharacters (semicolon, pipe, backticks, command substitution syntax) in the registry URL to break out of the intended npm audit command and execute arbitrary shell commands. No authentication or special privileges are required; a local user invoking the tool with a malicious registry argument can achieve code execution.

Affected products

  • jeemok better-npm-audit through 3.11.0, and 4.0.0-rc.2

Timeline

  • 2026-08-22: disclosed

References