NPM · JULY 2026 · EARLY WARNING

juggle npm Package Under Investigation for Remote Code Execution Vulnerability

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-67208Severity: CRITICAL

The juggle npm package version 1.6.0 is reportedly affected by a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands via the H2 database web console using default credentials.

What happened

An early warning has been issued regarding a critical vulnerability in the juggle npm package version 1.6.0. This vulnerability, tracked as CVE-2026-67208, allows unauthenticated remote attackers to execute arbitrary operating system commands. The attack leverages the exposed H2 database web console, which uses default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with these default credentials, and use the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, potentially resulting in root-level code execution when running the stock Docker image.

The severity of this vulnerability is rated as CRITICAL with a CVSS score of 9.8. It is under investigation, and the exact scope and impact are yet to be fully determined. Users of the juggle package are advised to upgrade to a version that is not affected by this vulnerability and to change the default credentials for the H2 database web console as a precautionary measure. For more detailed information, consult the primary sources linked in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If juggle is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats