A compromised Bitwarden CLI npm package allows a remote, anonymous attacker to steal credentials and exfiltrate sensitive information.
| Vendor | Product | Versions |
|---|---|---|
| bitwarden | bitwarden cli | 2026.4.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | bitwarden | cert_advisory | 90% |
Updated description with new details about credential theft and changed severity to HIGH.
Updated description with details on OS command injection and changed severity to CRITICAL.
Initial creation