utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
[
{
"source": "https://github.com/peterbraden/node-opencv/commit/aaece6921d7368577511f06c94c99dd4e9653563",
"target": {
"file": "src/FaceRecognizer.h"
},
"deprecated": false,
"id": "CVE-2019-10061-4c5c5caa",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"112452988723884673506501273598000269917",
"188992419719563020502915929919504129267",
"273346043374247195419051745256349540325",
"187460271573234866350606439562746424139"
]
}
}
]