Command Injection Vulnerability in npm-dependency-versions for Node.js
CVE-2022-29080
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 12 April 2022
What is CVE-2022-29080?
The npm-dependency-versions package, up to version 0.3.0 for Node.js, is susceptible to command injection attacks. An attacker could exploit this vulnerability by invoking the dependencyVersions function with a specifically crafted JSON object that includes shell metacharacters in a value associated with the pkgs key. This opens the door for potential malicious commands to be executed on the server, posing serious security risks.
