Lucene search

K
osvGoogleOSV:GHSA-M8FM-MV5W-33PV
HistoryMay 06, 2021 - 3:52 p.m.

Command Injection in psnode

2021-05-0615:52:59
Google
osv.dev
5
psnode
command injection
user input
kill function
arbitrary commands
child_process exec
input sanitization
software

EPSS

0.005

Percentile

76.1%

This affects all current versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

EPSS

0.005

Percentile

76.1%

Related for OSV:GHSA-M8FM-MV5W-33PV