Command Injection Vulnerability in npm-dependency-versions for Node.js
CVE-2022-29080

9.8CRITICAL

What is CVE-2022-29080?

The npm-dependency-versions package, up to version 0.3.0 for Node.js, is susceptible to command injection attacks. An attacker could exploit this vulnerability by invoking the dependencyVersions function with a specifically crafted JSON object that includes shell metacharacters in a value associated with the pkgs key. This opens the door for potential malicious commands to be executed on the server, posing serious security risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.