Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 01 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-01T04:06:17.153Z
Reserved: 2026-05-01T04:06:16.747Z
Link: CVE-2026-42994
No data.
Status : Received
Published: 2026-05-01T05:16:01.510
Modified: 2026-05-01T05:16:01.510
Link: CVE-2026-42994
No data.
OpenCVE Enrichment
No data.
Weaknesses