Executive brief
cdxgen is a tool that generates software bill-of-materials (SBOM) documents by analyzing source code and dependencies, commonly integrated into CI/CD pipelines. The Maven scanning feature contains a command injection flaw that allows an attacker controlling a repository to execute arbitrary shell commands when cdxgen processes the project, potentially compromising build infrastructure and accessing sensitive data.
Technical details
This is a command injection vulnerability (CWE-78, CWE-88) in the Maven project scanning component of cdxgen. The root cause is that Maven invocations were executed with shell: true on POSIX platforms, and attacker-controlled module paths from the repository were passed directly into shell command construction without proper escaping or validation. An attacker can exploit this by crafting a Maven project directory structure containing shell metacharacters (e.g., semicolons, pipes, backticks) that get interpreted by the shell when Maven is invoked. This affects both the CLI scanning mode and the server mode (POST /sbom endpoint), requiring only network access to the server (or local filesystem access for CLI) with no authentication or user interaction required. The fix in version 12.4.3 removes unconditional shell execution for Maven commands on POSIX systems and adds safeSpawnSync checks to block shell: true when command/argument values contain metacharacters.
Affected products
- CycloneDX @cyclonedx/cdxgen before 12.4.3
Timeline
- 2026-05-22: disclosed
- 2026-05-22: patched: Version 12.4.3 released with fix