juggle npm Package Under Investigation for Remote Code Execution Vulnerability
The juggle npm package version 1.6.0 is reportedly affected by a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands via the H2 database web console using default credentials.
What happened
An early warning has been issued regarding a critical vulnerability in the juggle npm package version 1.6.0. This vulnerability, tracked as CVE-2026-67208, allows unauthenticated remote attackers to execute arbitrary operating system commands. The attack leverages the exposed H2 database web console, which uses default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with these default credentials, and use the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, potentially resulting in root-level code execution when running the stock Docker image.
The severity of this vulnerability is rated as CRITICAL with a CVSS score of 9.8. It is under investigation, and the exact scope and impact are yet to be fully determined. Users of the juggle package are advised to upgrade to a version that is not affected by this vulnerability and to change the default credentials for the H2 database web console as a precautionary measure. For more detailed information, consult the primary sources linked in the threat data.
How 0Day mitigates this
juggle is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.