Lucene search

K
osvGoogleOSV:GHSA-VMQQ-7QVX-68QX
HistoryMay 24, 2022 - 5:09 p.m.

promise-probe OS command injection vulnerability

2022-05-2417:09:13
Google
osv.dev
5

7.5 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.

CPENameOperatorVersion
promise-probelt0.1.10

7.5 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

Related for OSV:GHSA-VMQQ-7QVX-68QX