CVE-2018-16462: Apex-Publish-Static-Files Project Apex-Publish-Static-Files

Critical severity, CVSS 10.0. EPSS: 7% chance of exploitation in the next 30 days.

A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.

Affected products

Published 2018-10-30. Last modified 2026-06-17.