GHSA-j665-rvj7-2jv9

Suggest an improvement
Source
https://github.com/advisories/GHSA-j665-rvj7-2jv9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-j665-rvj7-2jv9/GHSA-j665-rvj7-2jv9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j665-rvj7-2jv9
Aliases
  • CVE-2020-7672
Published
2021-05-17T21:00:17Z
Modified
2026-03-13T22:11:51.024104Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L CVSS Calculator
Summary
Code Injection in mosc
Details

mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to properties argument is executed by the eval function, resulting in code execution.

Database specific
{
    "cwe_ids": [
        "CWE-94"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2021-05-13T19:19:45Z",
    "nvd_published_at": "2020-06-10T16:15:00Z",
    "severity": "HIGH"
}
References

Affected packages

npm / mosc

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-j665-rvj7-2jv9/GHSA-j665-rvj7-2jv9.json"