Intel

AIKIDO-2026-655980

@lightdash/common is vulnerable to OS Command Injection

OS Command InjectionGHSA-gcx7-f5xr-8qmh Published Aug 20, 2026

88

High Risk

This Affects:

JS@lightdash/common
0.0.1 - 1.93.1
Fixed in 1.93.2
Are you affected? Scan for Free

TL;DR

Lightdash passes project-configured dbt environment variables into the dbt subprocess when compiling or running a project. The denylist that screens those variables is incomplete and is only applied when settings are saved, so stored values for keys such as GIT_PROXY_COMMAND, BASH_ENV, or loader variables like LD_PRELOAD reach the execution environment and can run externally supplied commands. A user who can update a project can set such a variable and obtain server-side command execution when dbt runs (for example when dbt deps invokes git). The fix adds an execution-time safe-environment builder, expands the blocked keys and prefixes, and ensures Lightdash-controlled DBT_* values cannot be overridden.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run Lightdash where users who can update a project are able to configure dbt environment variables through untrusted or externally influenced project settings.

Background info

@lightdash/common is vulnerable to OS Command Injection in versions 0.0.1 - 1.93.1.

How to fix this

Upgrade the @lightdash/common library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform