CVE-2026-42994

Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bitwarden:cli:2026.4.0:*:*:*:*:*:*:*

History

04 May 2026, 18:23

Type Values Removed Values Added
References () https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127 - () https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127 - Issue Tracking, Vendor Advisory
CWE CWE-94
First Time Bitwarden
Bitwarden cli
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:bitwarden:cli:2026.4.0:*:*:*:*:*:*:*

01 May 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-01 05:16

Updated : 2026-05-04 18:23


NVD link : CVE-2026-42994

Mitre link : CVE-2026-42994

CVE.ORG link : CVE-2026-42994


JSON object : View

Products Affected

bitwarden

  • cli
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')