Lucene search

K
osvGoogleOSV:GHSA-V2JV-33GH-XX29
HistoryMay 07, 2021 - 4:06 p.m.

Command Injection in ps-visitor

2021-05-0716:06:23
Google
osv.dev
11
ps-visitor
command injection
version 0.0.2
package
kill function
arbitrary commands
child_process exec
input sanitization
software

EPSS

0.005

Percentile

76.1%

This affects all versions up to and including version 0.0.2 of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

EPSS

0.005

Percentile

76.1%

Related for OSV:GHSA-V2JV-33GH-XX29