Critical Vulnerability in better-npm-audit: OS Command Injection via Registry Flag
A critical vulnerability, CVE-2026-57998, with a CVSS score of 7.8, was discovered in better-npm-audit, a popular npm package. The vulnerability allows for OS command injection via the --registry option, enabling attackers to execute arbitrary operating system commands with the privileges of the process running the audit. The vulnerability affects versions up to 3.11.0 and the 4.0.0-rc.2 prerelease. Immediate patching or mitigation is recommended to prevent potential exploitation.