HIGH
adaltas
CVE published 2026-08-05
CVE-2026-71243
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T11:16:27.247Z and has not been modified since then. The backmeup npm package is vulnerable to arbitrary OS command execution due to improper handling of shell command strings. The package concatenates option values (name, source, destination, filter) without neutralizing shell metacharacters, all [truncated]