CVE-2026-42994: OS Command Injection
Published May 1, 2026
·Updated
Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.
Affected Software
2 affected components
npm/bitwarden-cli=2026.4.0
Bitwarden CLI=2026.4.0
Event History
May 1, 2026
CVE Published
via MITRE·04:06 AM
Data Sourced
via MITRE·04:06 AM
DescriptionWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-42994?
CVE-2026-42994 has been classified with a high severity due to the presence of embedded malicious code in the Bitwarden CLI.
2
How do I fix CVE-2026-42994?
To remediate CVE-2026-42994, users should uninstall version 2026.4.0 of Bitwarden CLI and install a secure version from a trusted source.
3
What software is affected by CVE-2026-42994?
CVE-2026-42994 affects Bitwarden CLI version 2026.4.0 obtained from npm.
4
What type of vulnerability is CVE-2026-42994?
CVE-2026-42994 is a supply chain vulnerability related to malicious code being embedded within the software package.
5
When was CVE-2026-42994 introduced?
CVE-2026-42994 was introduced in Bitwarden CLI version 2026.4.0, released on April 22, 2026.