CVE-2026-71243: Adaltas Backmeup

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = "mkdir -p " + path.join(info.destination, info.name) + "; " - and executes the resulting string through a shell via ssh2-exec (locally via child_process, or remotely via SSH when an ssh handle is supplied), rather than using execFile/spawn with an argument array.

Affected products

  • Adaltas Backmeup: up to and including 0.0.2

Published 2026-08-05. Last modified 2026-08-26.