GHSA-cv76-rv4h-4mqc

Suggest an improvement
Source
https://github.com/advisories/GHSA-cv76-rv4h-4mqc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-cv76-rv4h-4mqc/GHSA-cv76-rv4h-4mqc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cv76-rv4h-4mqc
Aliases
Published
2022-06-03T00:00:59Z
Modified
2023-11-08T04:06:07Z
Summary
OS Command Injection in proctree
Details

OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.

Database specific
{
    "cwe_ids":  [
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-06-03T22:24:14Z",
    "nvd_published_at":  "2022-06-02T14:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / proctree

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.1.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-cv76-rv4h-4mqc/GHSA-cv76-rv4h-4mqc.json"