Lucene search

K
osvGoogleOSV:GHSA-WHQ6-MJ2R-MJQC
HistoryApr 13, 2021 - 3:17 p.m.

OS Command Injection in lsof

2021-04-1315:17:53
Google
osv.dev
58
os command injection
lsof npm
exec function
software vulnerability

EPSS

0.013

Percentile

86.2%

All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.

EPSS

0.013

Percentile

86.2%

Related for OSV:GHSA-WHQ6-MJ2R-MJQC