CVE-2026-42994
CVSS 9.8 CRITICAL: bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. EPSS 0.5% (43º percentile).
Vulnerabilità · 133 giorni fa
La vera compromissione non è stata un difetto di codice. Un percorso di installazione npm fidato è stato trasformato in un evento di breve durata di raccolta di segreti e, quando CVE-2026-42994 è comparsa nei dashboard, la finestra di furto delle credenziali era già chiusa. Una vista SCA pulita non significava che la macchina dello sviluppatore o il runner CI fossero puliti.
CVSS 9.8 CRITICAL: bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. EPSS 0.5% (43º percentile).
1 fonte che coprono questa storia
Why some security fixes never reach your vulnerability dashboard
CVE was built to track code flaws with fixes. It’s now being stretched to cover malware and supply chain incidents that don’t fit. Agent infrastructure and AI assets are where that drift becomes structural.
Part of the PlainSec briefing for 2026-05-21