Lucene search

K
osvGoogleOSV:GHSA-H2P3-H48H-9JJ7
HistoryMay 13, 2022 - 1:41 a.m.

PIDUsage Enables OS Command Injection

2022-05-1301:41:00
Google
osv.dev
4

9.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.8%

Overview

Affected versions of pidusage pass unsanitized input to child_process.exec(), resulting in arbitrary code execution in the ps method.

This package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX.

Windows and Linux are not vulnerable.

Proof of Concept

var pid = require('pidusage');
pid.stat('1 && /usr/local/bin/python');

Remediation

Update to version 1.1.5 or later.

CPENameOperatorVersion
pidusagele1.1.4

9.7 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

65.8%

Related for OSV:GHSA-H2P3-H48H-9JJ7