CVE-2026-32948 | sbt up to 1.12.6 os command injection
A vulnerability, which was classified as critical, has been found in sbt up to 1.12.6. Affected is an unknown function. Performing a manipulation results in os command injection.
This vulnerability is reported as CVE-2026-32948. The attack requires a local approach. No exploit exists.
It is advisable to upgrade the affected component.