A vulnerability marked as problematic has been reported in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument –branch causes os command injection.

This vulnerability is tracked as CVE-2026-16733. The attack is restricted to local execution. Moreover, an exploit is present.

The project was informed of the problem early through an issue report but has not responded yet.