CVE-2026-42994
CVSS 9.8 CRITICAL: bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. EPSS 0.5% (43º percentile).
Vulnerabilità ed exploit · Supply chain
La vera compromissione non è stata un difetto di codice. Un percorso di installazione npm fidato è stato trasformato in un evento di breve durata di raccolta di segreti e, quando CVE-2026-42994 è comparsa nei dashboard, la finestra di furto delle credenziali era già chiusa. Una vista SCA pulita non significava che la macchina dello sviluppatore o il runner CI fossero puliti.
1 fonte · 20 mag
CVSS 9.8 CRITICAL: bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. EPSS 0.5% (43º percentile).
CSO Online
Why some security fixes never reach your vulnerability dashboard
CVE was built to track code flaws with fixes. It’s now being stretched to cover malware and supply chain incidents that don’t fit. Agent infrastructure and AI assets are where that drift becomes structural.
originalePart of the PlainSec briefing for 2026-05-21
Every edition of this story: Rilascio malevolo su npm ha esposto segreti prima che apparisse una CVE