CVE-2026-42994

· NIST NVD ↗

Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.

CRITICAL
CVSS severity
9.8
CVSS base score
2026-05-01
Published

CWE codes

CWE-78CWE-94

Affected products

bitwarden:cli

Sources