Lucene search

K
osvGoogleOSV:GHSA-5FW9-FQ32-WV5P
HistoryDec 21, 2020 - 4:04 p.m.

OS Command Injection in node-notifier

2020-12-2116:04:07
Google
osv.dev
21

0.002 Low

EPSS

Percentile

57.6%

This affects the package node-notifier before 8.0.1. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.

CPENameOperatorVersion
node-notifierlt8.0.1

0.002 Low

EPSS

Percentile

57.6%