GHSA-88h9-fc6v-jcw7

Suggest an improvement
Source
https://github.com/advisories/GHSA-88h9-fc6v-jcw7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-88h9-fc6v-jcw7/GHSA-88h9-fc6v-jcw7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-88h9-fc6v-jcw7
Published
2020-09-03T20:28:51Z
Modified
2020-08-31T18:49:17Z
Summary
Unintended Require in larvitbase-www
Details

All versions of larvitbase-www are vulnerable to an Unintended Require. The package exposes an API endpoint and passes a GET parameter unsanitized to an require() call. This allows attackers to execute any .js file in the same folder as the server is running.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:49:17Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / larvitbase-www

Package

Name
larvitbase-www
View open source insights on deps.dev
Purl
pkg:npm/larvitbase-www

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-88h9-fc6v-jcw7/GHSA-88h9-fc6v-jcw7.json"